Skip to content
CVSS 9.9 · CRITICAL

CVE-2026-48752Escape de contenedor a host en Incus mediante imágenes maliciosas

Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image or instance backup can be used to read or create/write arbitrary files on the host; possibly leading to arbitrary command execution. Version 7.2.0 patches the issue.

Ver en NVD

Análisis

Incus (successor to LXD) is vulnerable to a host filesystem escape via crafted images or backups. This allows an attacker to read or write arbitrary files on the host system, potentially leading to full remote code execution on the host.

Roles relevantes

LinuxCloudciberseguridadBackendDocker

Severidad

Puntaje: 9.9(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: LOW
UI: NONE
S: CHANGED
C: HIGH
I: HIGH
A: HIGH
Tipo de falla (CWE): CWE-73

EPSS

Sin puntaje EPSS aún (CVE muy reciente).

Descripción técnica

Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image or instance backup can be used to read or create/write arbitrary files on the host; possibly leading to arbitrary command execution. Version 7.2.0 patches the issue.

Publicada: 21/8/2026, 15:16:40
Última modificación: 21/8/2026, 15:16:40

Referencias

InicioEventosBlogRecursosCursosEquipo