<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T16:07:12.012214+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-15476</id>
    <title>bdu:2026-15476</title>
    <updated>2026-10-04T16:07:12.016636+00:00</updated>
    <content>bdu:2026-15476</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-15476"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-357330</id>
    <title>EUVD-2026-357330</title>
    <updated>2026-10-04T16:07:12.016683+00:00</updated>
    <content>EUVD-2026-357330</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-357330"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-47753</id>
    <title>fkie_cve-2026-47753</title>
    <updated>2026-10-04T16:07:12.016706+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Incus is a system container and virtual machine manager. Prior to version 7.1.0, `(*backend).CreateInstanceFromBackup` in `internal/server/storage/backend.go` contains a nil-pointer dereference that an authenticated user with permission to create instances in any project can trigger remotely by uploading a crafted backup tarball. The Incus daemon panics and the process crashes, causing denial of service to every project on that cluster member. This is a sibling of `GHSA-fwj8-62r8-8p8m`, `GHSA-r7w7-mmxr-47r9`, and `GHSA-x5r6-jr56-89pv` (all assigned 2026-05-04). Those patches added guards on adjacent fields of the same `backup/config.Config` struct; the `Volume` field on the instance-import path was missed. Version 7.1.0 contains an updated patch.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-47753"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-8g7m-96c8-8wwc</id>
    <title>GHSA-8g7m-96c8-8wwc — Incus has a Nil-Pointer Dereference Panic via Instance Backup Import (volume omitted)</title>
    <updated>2026-10-04T16:07:12.016749+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/lxc/incus/v7</p>
<p>## Summary</p>
<p>`(*backend).CreateInstanceFromBackup` in [`internal/server/storage/backend.go`](https://github.com/lxc/incus/blob/1513600/internal/server/storage/backend.go) contains a nil-pointer dereference that an authenticated user with permission to create instances in any project can trigger remotely by uploading a crafted backup tarball. The Incus daemon panics and the process crashes, causing denial of service to every project on that cluster member.</p>
<p>This is a sibling of `GHSA-fwj8-62r8-8p8m`, `GHSA-r7w7-mmxr-47r9`, and `GHSA-x5r6-jr56-89pv` (all assigned 2026-05-04). Those patches added guards on adjacent fields of the same `backup/config.Config` struct; the `Volume` field on the instance-import path was missed.</p>
<p>## Vulnerable code</p>
<p>[`internal/server/storage/backend.go`](https://github.com/lxc/incus/blob/1513600/internal/server/storage/backend.go) (current `main`, commit `1513600`):</p>
<p>```go
// Lines 763-767 — properly guarded:
var volumeConfig map[string]string
if srcBackup.Config != nil &amp;&amp; srcBackup.Config.Volume != nil {
    volumeConfig = srcBackup.Config.Volume.Config
}</p>
<p>// ... a few lines later ...</p>
<p>// Line 795 — unguarded, dereferences Config.Volume directly:
if srcBackup.Config.Volume.Config["block.type"] == drivers.BlockVolumeTypeQcow2 {
```</p>
<p>The caller `createFromBackup` in [`cmd/incusd/instances_post.go`](https://github.com/lxc/incus/blob/1513600/cmd/incusd/instances_post.go) only verifies that `Config` and `Config.Container` are non-nil:</p>
<p>```go
// instances_p…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-8g7m-96c8-8wwc"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11651-1</id>
    <title>openSUSE-SU-2026:11651-1 — incus-7.4-1.1 on GA media</title>
    <updated>2026-10-04T16:07:12.016823+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>incus-7.4-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11651-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-47753</id>
    <title>UBUNTU-CVE-2026-47753</title>
    <updated>2026-10-04T16:07:12.016849+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:24.04:LTS: incus, Ubuntu:25.10: incus, Ubuntu:Pro:26.04:LTS: incus</p>
<p>Incus is a system container and virtual machine manager. Prior to version 7.1.0, `(*backend).CreateInstanceFromBackup` in `internal/server/storage/backend.go` contains a nil-pointer dereference that an authenticated user with permission to create instances in any project can trigger remotely by uploading a crafted backup tarball. The Incus daemon panics and the process crashes, causing denial of service to every project on that cluster member. This is a sibling of `GHSA-fwj8-62r8-8p8m`, `GHSA-r7w7-mmxr-47r9`, and `GHSA-x5r6-jr56-89pv` (all assigned 2026-05-04). Those patches added guards on adjacent fields of the same `backup/config.Config` struct; the `Volume` field on the instance-import path was missed. Version 7.1.0 contains an updated patch.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-47753"/>
  </entry>
</feed>
