PT-2026-28522 · Incus+1 · Incus+1
Stamparm
·
Published
2026-01-01
·
Updated
2026-05-04
·
CVE-2026-33743
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Incus versions prior to 6.23.0
Description
Incus, a system container and virtual machine manager, contains a flaw where a specially crafted storage bucket backup can be used by a user with access to the storage bucket feature to crash the Incus daemon. Repeated exploitation of this issue can lead to a denial of service of the control plane API. This does not affect running containers or virtual machines. The issue is due to an unchecked string slicing vulnerability in the S3 transfer manager, specifically during S3 restore operations. The code fails to validate header names before slicing strings, and a malicious archive containing a header name shorter than expected can trigger a slice-bounds panic, terminating the daemon. The vulnerable code is located in the
UploadAllFiles function within the internal/server/storage/s3/transfer manager.go file.Recommendations
Update Incus to version 6.23.0 or later.
Exploit
Fix
DoS
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Incus
Red Os