Upstream information

CVE-2026-63343 at MITRE

Description

Incus is a system container and virtual machine manager. Prior to version 7.3.0, a malicious image containing a `metadata.yaml` symlink pointing to an arbitrary host path allows an authenticated Incus user to read or overwrite any file on the host as root via the instance metadata API. The `exec-output` and `templates/` paths were patched in a prior release using `Lstat` rejection and `os.OpenRoot` confinement; `metadata.yaml` was not included in either patch and remains exploitable. Version 7.3.0 patches the issue.

SUSE information

Overall state of this security issue: Resolved

This issue is currently rated as having critical severity.

CVSS v3 Scores
CVSS detail CNA (GitHub)
Base Score 9.9
Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Attack Vector Network
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Changed
Confidentiality Impact High
Integrity Impact High
Availability Impact High
CVSSv3 Version 3.1
SUSE Bugzilla entry: 1276251 [NEW]

No SUSE Security Announcements cross referenced.

List of released packages

Product(s) Fixed package version(s) References
openSUSE Tumbleweed
  • incus >= 7.4-1.1
  • incus-cli >= 7.4-1.1
  • incus-cli-bash-completion >= 7.4-1.1
  • incus-cli-fish-completion >= 7.4-1.1
  • incus-cli-zsh-completion >= 7.4-1.1
  • incus-tools >= 7.4-1.1
Patchnames:
openSUSE-Tumbleweed-2026-11651


SUSE Timeline for this CVE

CVE page created: Mon Aug 24 11:41:17 2026
CVE page last modified: Tue Sep 1 11:51:04 2026