CVE-2026-47753Medium▾ SunlitIncus is a system container and virtual machine manager. Prior to version 7.1.0, `(*backend).CreateInstanceFromBackup` in `internal/server/storage/backend.go` contains a nil-pointer dereference that an authenticated user with permission …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 22.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.1%
Last analysed / modified upstream
0.1% → 0.3%
Incus is a system container and virtual machine manager. Prior to version 7.1.0, (*backend).CreateInstanceFromBackup in internal/server/storage/backend.go contains a nil-pointer dereference that an authenticated user with permission to create instances in any project can trigger remotely by uploading a crafted backup tarball. The Incus daemon panics and the process crashes, causing denial of service to every project on that cluster member. This is a sibling of GHSA-fwj8-62r8-8p8m, GHSA-r7w7-mmxr-47r9, and GHSA-x5r6-jr56-89pv (all assigned 2026-05-04). Those patches added guards on adjacent fields of the same backup/config.Config struct; the Volume field on the instance-import path was missed. Version 7.1.0 contains an updated patch.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
github.com/lxc/incus/v7 < 7.1.0Patched in:
github.com/lxc/incus/v7 7.1.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-55621High· 7.7Incus is a system container and virtual machine manager
CVE-2026-48754LowIncus is a system container and virtual machine manager
CVE-2026-48756LowIncus is a system container and virtual machine manager
CVE-2021-3739High· 7.1A NULL pointer dereference flaw was found in the btrfs_rm_device function in fs/btrfs/volumes.c in the Linux Kernel, where triggering the bug requires ‘CAP_SYS_ADMIN’
CVE-2026-55622High· 7.7Incus is a system container and virtual machine manager
CVE-2026-1584High· 7.5A flaw was found in gnutls