CVE-2026-23954
Incus container image templating arbitrary host file read and write in github.com/lxc/incus
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/lxc/incus/security/advisories/GHSA-7f67-crqm-jgh7, https://nvd.nist.gov/vuln/detail/CVE-2026-23954, https://github.com/lxc/incus/blob/HEAD/internal/server/instance/drivers/driverlxc.go#L7215, https://github.com/lxc/incus/blob/HEAD/internal/server/instance/drivers/driverlxc.go#L7294, https://github.com/user-attachments/files/24473599/templatearbitrarywrite.sh, https://github.com/user-attachments/files/24473601/templatesarbitrarywrite.patch
