<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 04:02:49 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-07367</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-07367</link>
      <description>bdu:2026-07367</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-07367</guid>
    </item>
    <item>
      <title>EUVD-2026-277887</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-277887</link>
      <description>EUVD-2026-277887</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-277887</guid>
    </item>
    <item>
      <title>fkie_cve-2026-33945</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-33945</link>
      <description>&lt;p&gt;Incus is a system container and virtual machine manager. Incus instances have an option to provide credentials to systemd in the guest. For containers, this is handled through a shared directory. Prior to version 6.23.0, an attacker can set a configuration key named something like `systemd.credential.../../../../../../root/.bashrc` to cause Incus to write outside of the `credentials` directory associated with the container. This makes use of the fact that the Incus syntax for such credentials is `systemd.credential.XYZ` where `XYZ` can itself contain more periods. While it&amp;#39;s not possible to read any data this way, it&amp;#39;s possible to write to arbitrary files as root, enabling both privilege escalation and denial of service attacks. Version 6.23.0 fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Incus is a system container and virtual machine manager. Incus instances have an option to provide credentials to systemd in the guest. For containers, this is handled through a shared directory. Prior to version 6.23.0, an attacker can set a configuration key named something like `systemd.credential.../../../../../../root/.bashrc` to cause Incus to write outside of the `credentials` directory associated with the container. This makes use of the fact that the Incus syntax for such credentials is `systemd.credential.XYZ` where `XYZ` can itself contain more periods. While it&amp;#39;s not possible to read any data this way, it&amp;#39;s possible to write to arbitrary files as root, enabling both privilege escalation and denial of service attacks. Version 6.23.0 fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-33945</guid>
    </item>
    <item>
      <title>GHSA-q4q8-7f2j-9h9f — Incus has an abitrary file write through its systemd-creds options</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-q4q8-7f2j-9h9f</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/lxc/incus/v6&lt;/p&gt;
&lt;p&gt;### Summary
Incus instances have an option to provide credentials to systemd in the guest. For containers, this is handled through a shared directory.
An attacker can use the name of a systemd credential to escape that directory and overwrite arbitrary files on the host system.&lt;/p&gt;
&lt;p&gt;This can in turn be used to perform local privilege escalation or cause a DoS.&lt;/p&gt;
&lt;p&gt;### Details
An attacker can set a configuration key named something like `systemd.credential.../../../../../../root/.bashrc` to cause Incus to write outside of the `credentials` directory associated with the container. This makes use of the fact that the Incus syntax for such credentials is `systemd.credential.XYZ` where `XYZ` can itself contain more periods.&lt;/p&gt;
&lt;p&gt;While it&amp;#39;s not possible to read any data this way, it&amp;#39;s possible to write to arbitrary files as root, enabling both privilege escalation and denial of service attacks.&lt;/p&gt;
&lt;p&gt;### Credit
This issue was discovered and reported by the team at [7asecurity](https://7asecurity.com/)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/lxc/incus/v6&lt;/p&gt;
&lt;p&gt;### Summary
Incus instances have an option to provide credentials to systemd in the guest. For containers, this is handled through a shared directory.
An attacker can use the name of a systemd credential to escape that directory and overwrite arbitrary files on the host system.&lt;/p&gt;
&lt;p&gt;This can in turn be used to perform local privilege escalation or cause a DoS.&lt;/p&gt;
&lt;p&gt;### Details
An attacker can set a configuration key named something like `systemd.credential.../../../../../../root/.bashrc` to cause Incus to write outside of the `credentials` directory associated with the container. This makes use of the fact that the Incus syntax for such credentials is `systemd.credential.XYZ` where `XYZ` can itself contain more periods.&lt;/p&gt;
&lt;p&gt;While it&amp;#39;s not possible to read any data this way, it&amp;#39;s possible to write to arbitrary files as root, enabling both privilege escalation and denial of service attacks.&lt;/p&gt;
&lt;p&gt;### Credit
This issue was discovered and reported by the team at [7asecurity](https://7asecurity.com/)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-q4q8-7f2j-9h9f</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10450-1 — incus-6.23-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10450-1</link>
      <description>&lt;p&gt;incus-6.23-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;incus-6.23-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10450-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-33945</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-33945</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:24.04:LTS: incus, Ubuntu:25.10: incus, Ubuntu:Pro:26.04:LTS: incus&lt;/p&gt;
&lt;p&gt;Incus is a system container and virtual machine manager. Incus instances have an option to provide credentials to systemd in the guest. For containers, this is handled through a shared directory. Prior to version 6.23.0, an attacker can set a configuration key named something like `systemd.credential.../../../../../../root/.bashrc` to cause Incus to write outside of the `credentials` directory associated with the container. This makes use of the fact that the Incus syntax for such credentials is `systemd.credential.XYZ` where `XYZ` can itself contain more periods. While it&amp;#39;s not possible to read any data this way, it&amp;#39;s possible to write to arbitrary files as root, enabling both privilege escalation and denial of service attacks. Version 6.23.0 fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:24.04:LTS: incus, Ubuntu:25.10: incus, Ubuntu:Pro:26.04:LTS: incus&lt;/p&gt;
&lt;p&gt;Incus is a system container and virtual machine manager. Incus instances have an option to provide credentials to systemd in the guest. For containers, this is handled through a shared directory. Prior to version 6.23.0, an attacker can set a configuration key named something like `systemd.credential.../../../../../../root/.bashrc` to cause Incus to write outside of the `credentials` directory associated with the container. This makes use of the fact that the Incus syntax for such credentials is `systemd.credential.XYZ` where `XYZ` can itself contain more periods. While it&amp;#39;s not possible to read any data this way, it&amp;#39;s possible to write to arbitrary files as root, enabling both privilege escalation and denial of service attacks. Version 6.23.0 fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-33945</guid>
    </item>
  </channel>
</rss>
