Description
Incus is a system container and virtual machine manager. Prior to version 7.0.0, uploads of large amount of data by authenticated users can run the Incus server out of disk space, potentially taking down the host system. The impact here is limited for anyone using storage.images_volume and storage.backups_volume as those users will have large uploads be stored on those volumes rather than directly on the host filesystem. This is the default behavior on IncusOS. This issue has been patched in version 7.0.0.
References (2)
Core 2
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/lxc/incus/security/advisories/GHSA-98vh-x9cx-9cfp
X_Refsource_Misc x_refsource_misc
https://github.com/lxc/incus/releases/tag/v7.0.0
Scores
CVSS v3
4.3
EPSS
0.0001
EPSS Percentile
3.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-770
Status
published
Products (3)
linuxcontainers/incus
< 7.0.0
lxc/incus
0 - 6.23.0Go
lxc/incus
< 7.0.0
Published
May 07, 2026
Tracked Since
May 07, 2026