PT-2026-37138 · Incus+1 · Incus+1

·

CVE-2026-41648

·

Published

2026-05-01

·

Updated

2026-07-30

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Incus versions prior to 7.0.0
Description Incus is a system container and virtual machine manager. An authenticated user can provide a specially crafted image or backup tarball containing a very large YAML document. Because the software unpacks these tarballs and parses YAML files without size restrictions, the document can be loaded into memory, potentially causing the server to run out of memory and degrade service. This occurs because the getImageMetadata() and backup.GetInfo() functions call the YAML decoder directly on the tar reader without limiting the bytes consumed or checking the hdr.Size of the tar entry. While the system mitigates alias and anchor bombs, large flat YAML documents can still cause memory consumption approximately 5x to 6x the input size.
Recommendations Update to version 7.0.0.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-09656
CVE-2026-41648
GHSA-67WX-R9XR-X75X
GO-2026-5168
OPENSUSE-SU-2026:21483-1

Affected Products

Incus
Red Os