PT-2025-46210 · Incus+2 · Incus+2

Abdodz1234

·

Published

2025-11-10

·

Updated

2026-04-20

·

CVE-2025-64507

CVSS v4.0

8.6

High

VectorAV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Incus versions prior to 6.0.6 and 6.19.0 LXD versions prior to 5.0.2-5+deb12u2 Incus versions prior to 6.0.4-2+deb13u2
Description Incus, a system container and virtual machine manager, has a flaw that could allow local privilege escalation. This issue affects systems where an unprivileged user has root access to a container with a custom storage volume that has the security.shifted property set to true, and also has access to the host as an unprivileged user. Specifically, users may be able to create a custom storage volume and write a setuid binary within the container, which can then be executed on the host to gain root privileges. The issue also affects LXD, another system container and virtual machine manager, when unprivileged users access it through lxd-user.
Recommendations Upgrade Incus to version 6.0.6 or 6.19.0. Upgrade LXD to version 5.0.2-5+deb12u2. Upgrade Incus to version 6.0.4-2+deb13u2. As a temporary workaround, manually restrict permissions using the following commands: chmod 0700 /var/lib/incus/storage-pools// chmod 0711 /var/lib/incus/storage-pools//buckets chmod 0711 /var/lib/incus/storage-pools//container

Exploit

Fix

LPE

Improper Privilege Management

Weakness Enumeration

Related Identifiers

BDU:2025-16114
CVE-2025-64507
DSA-6051-1
DSA-6057-1
GHSA-56MX-8G9F-5CRF
GO-2025-4115

Affected Products

Debian
Incus
Red Os