CVE-2026-33897

Description

A flaw was found in Incus, a system container and virtual machine manager. An attacker with control over instance template files can exploit a vulnerability in the pongo2 templating engine. This flaw allows for arbitrary read or write operations as the root user on the host server by bypassing the intended chroot isolation mechanism. This can lead to unauthorized access and modification of critical system files.

Statement

This Important flaw in Incus, a system container and virtual machine manager, allows an attacker with control over instance template files to bypass chroot isolation. This enables arbitrary file read or write operations as the root user on the host server. This vulnerability affects Incus, which is available as a community project.

Understanding the Weakness (CWE)

Confidentiality

Technical Impact: Read Files or Directories

Frequently Asked Questions

Want to get errata notifications? Sign up here.