Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-6407-1 | incus security update |
Fri, 21 Aug 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Incus is a system container and virtual machine manager. Prior to version 7.3.0, a malicious image containing a `metadata.yaml` symlink pointing to an arbitrary host path allows an authenticated Incus user to read or overwrite any file on the host as root via the instance metadata API. The `exec-output` and `templates/` paths were patched in a prior release using `Lstat` rejection and `os.OpenRoot` confinement; `metadata.yaml` was not included in either patch and remains exploitable. Version 7.3.0 patches the issue. | |
| Title | Arbitrary File Read/Write: metadata.yaml symlink in image allows host filesystem access as root | |
| Weaknesses | CWE-73 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-21T14:53:26.109Z
Reserved: 2026-07-16T14:14:24.385Z
Link: CVE-2026-63343
No data.
Status : Received
Published: 2026-08-21T15:16:46.577
Modified: 2026-08-21T15:16:46.577
Link: CVE-2026-63343
No data.
OpenCVE Enrichment
No data.
Debian DSA