DEBIAN-CVE-2026-62867
Incus is a system container and virtual machine manager. Prior to version 7.3.0, improper validation of user-provided block.create_options in storage volume configuration leads to argument injection in the constructed filesystem creation command line. This allows a project-scoped user to inject arbitrary arguments into the binary executed as root. Version 7.3.0 patches the issue.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://security-tracker.debian.org/tracker/CVE-2026-62867