CVE-2026-48769RCE como root en Incus mediante servidor de imágenes malicioso
Incus is a system container and virtual machine manager. Prior to version 7.2.0, an arbitrary file write exists in the Incus client when a malicious image server returns a crafted `Incus-Image-Hash` header. This can lead to arbitrary command execution as root on the server. Version 7.2.0 patches the issue.
Ver en NVDAnálisis
Incus, el sucesor comunitario de LXD para gestión de contenedores y VMs, presenta una vulnerabilidad de severidad crítica (9.9). Un servidor de imágenes malicioso puede provocar una escritura de archivos arbitrarios que resulta en ejecución de comandos con privilegios de root en el host. Se recomienda actualizar a la versión 7.2.0.
Severidad
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HCWE-20EPSS
Sin puntaje EPSS aún (CVE muy reciente).
Descripción técnica
Incus is a system container and virtual machine manager. Prior to version 7.2.0, an arbitrary file write exists in the Incus client when a malicious image server returns a crafted `Incus-Image-Hash` header. This can lead to arbitrary command execution as root on the server. Version 7.2.0 patches the issue.