<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 22:51:58 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-00871</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-00871</link>
      <description>bdu:2026-00871</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-00871</guid>
    </item>
    <item>
      <title>EUVD-2026-266629</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-266629</link>
      <description>EUVD-2026-266629</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-266629</guid>
    </item>
    <item>
      <title>fkie_cve-2026-23954</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-23954</link>
      <description>&lt;p&gt;Incus is a system container and virtual machine manager. Versions 6.21.0 and below allow a user with the ability to launch a container with a custom image (e.g a member of the ‘incus’ group) to use directory traversal or symbolic links in the templating functionality to achieve host arbitrary file read, and host arbitrary file write. This ultimately results in arbitrary command execution on the host. When using an image with a metadata.yaml containing templates, both the source and target paths are not checked for symbolic links or directory traversal. This can also be exploited in IncusOS. A fix is planned for versions 6.0.6 and 6.21.0, but they have not been released at the time of publication.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Incus is a system container and virtual machine manager. Versions 6.21.0 and below allow a user with the ability to launch a container with a custom image (e.g a member of the ‘incus’ group) to use directory traversal or symbolic links in the templating functionality to achieve host arbitrary file read, and host arbitrary file write. This ultimately results in arbitrary command execution on the host. When using an image with a metadata.yaml containing templates, both the source and target paths are not checked for symbolic links or directory traversal. This can also be exploited in IncusOS. A fix is planned for versions 6.0.6 and 6.21.0, but they have not been released at the time of publication.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-23954</guid>
    </item>
    <item>
      <title>GHSA-7f67-crqm-jgh7 — Incus container image templating arbitrary host file read and write</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-7f67-crqm-jgh7</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/lxc/incus/v6/cmd/incusd&lt;/p&gt;
&lt;p&gt;### Summary
A user with the ability to launch a container with a custom image (e.g a member of the ‘incus’ group) can use directory traversal or symbolic links in the templating functionality to achieve host arbitrary file read, and host arbitrary file write, ultimately resulting in arbitrary command execution on the host. This can also be exploited in IncusOS.&lt;/p&gt;
&lt;p&gt;### Details
When using an image with a `metadata.yaml` containing templates, both the source and target paths are not checked for symbolic links or directory traversal. [1] [2] For example, the following `metadata.yaml` snippet can read an arbitrary file from the host root filesystem as root, and place it inside the container:&lt;/p&gt;
&lt;p&gt;```
templates:
  /shadow:
    when:
      - start
    template: ../../../../../../../../etc/shadow
```&lt;/p&gt;
&lt;p&gt;Additionally, the path of the target of the template is not checked or opened safely, and can therefore contain symbolic links pointing outside the container root filesystem. For example:&lt;/p&gt;
&lt;p&gt;```
templates:
 /realroot/proc/sys/kernel/core_pattern:
    when:
      - start
    template: core_pattern.tpl
```&lt;/p&gt;
&lt;p&gt;Where the container root filesystem contains a symbolic link named `/realroot` pointing to `/`. This will cause the contents of the template (from the normal &amp;#34;templates&amp;#34; directory in this case) to be written to the host root filesystem as root.&lt;/p&gt;
&lt;p&gt;This can be exploited to achieve arbitrary command execution on the host by overwriting key files. In the provided proof of concept, I am overwriting…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/lxc/incus/v6/cmd/incusd&lt;/p&gt;
&lt;p&gt;### Summary
A user with the ability to launch a container with a custom image (e.g a member of the ‘incus’ group) can use directory traversal or symbolic links in the templating functionality to achieve host arbitrary file read, and host arbitrary file write, ultimately resulting in arbitrary command execution on the host. This can also be exploited in IncusOS.&lt;/p&gt;
&lt;p&gt;### Details
When using an image with a `metadata.yaml` containing templates, both the source and target paths are not checked for symbolic links or directory traversal. [1] [2] For example, the following `metadata.yaml` snippet can read an arbitrary file from the host root filesystem as root, and place it inside the container:&lt;/p&gt;
&lt;p&gt;```
templates:
  /shadow:
    when:
      - start
    template: ../../../../../../../../etc/shadow
```&lt;/p&gt;
&lt;p&gt;Additionally, the path of the target of the template is not checked or opened safely, and can therefore contain symbolic links pointing outside the container root filesystem. For example:&lt;/p&gt;
&lt;p&gt;```
templates:
 /realroot/proc/sys/kernel/core_pattern:
    when:
      - start
    template: core_pattern.tpl
```&lt;/p&gt;
&lt;p&gt;Where the container root filesystem contains a symbolic link named `/realroot` pointing to `/`. This will cause the contents of the template (from the normal &amp;#34;templates&amp;#34; directory in this case) to be written to the host root filesystem as root.&lt;/p&gt;
&lt;p&gt;This can be exploited to achieve arbitrary command execution on the host by overwriting key files. In the provided proof of concept, I am overwriting…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-7f67-crqm-jgh7</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10280-1 — incus-6.22-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10280-1</link>
      <description>&lt;p&gt;incus-6.22-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;incus-6.22-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10280-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-23954</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-23954</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: lxd, Ubuntu:Pro:18.04:LTS: lxd, Ubuntu:20.04:LTS: lxd, Ubuntu:Pro:24.04:LTS: incus, Ubuntu:25.10: incus, Ubuntu:Pro:26.04:LTS: incus&lt;/p&gt;
&lt;p&gt;Incus is a system container and virtual machine manager. Versions 6.21.0 and below allow a user with the ability to launch a container with a custom image (e.g a member of the ‘incus’ group) to use directory traversal or symbolic links in the templating functionality to achieve host arbitrary file read, and host arbitrary file write. This ultimately results in arbitrary command execution on the host. When using an image with a metadata.yaml containing templates, both the source and target paths are not checked for symbolic links or directory traversal. This can also be exploited in IncusOS. A fix is planned for versions 6.0.6 and 6.21.0, but they have not been released at the time of publication.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: lxd, Ubuntu:Pro:18.04:LTS: lxd, Ubuntu:20.04:LTS: lxd, Ubuntu:Pro:24.04:LTS: incus, Ubuntu:25.10: incus, Ubuntu:Pro:26.04:LTS: incus&lt;/p&gt;
&lt;p&gt;Incus is a system container and virtual machine manager. Versions 6.21.0 and below allow a user with the ability to launch a container with a custom image (e.g a member of the ‘incus’ group) to use directory traversal or symbolic links in the templating functionality to achieve host arbitrary file read, and host arbitrary file write. This ultimately results in arbitrary command execution on the host. When using an image with a metadata.yaml containing templates, both the source and target paths are not checked for symbolic links or directory traversal. This can also be exploited in IncusOS. A fix is planned for versions 6.0.6 and 6.21.0, but they have not been released at the time of publication.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-23954</guid>
    </item>
  </channel>
</rss>
