CVE-2026-62313

Description

A flaw was found in Incus, a system container and virtual machine manager. A user within a project configured to forbid non-isolated containers can bypass this restriction by omitting a specific security setting (security.idmap.isolated). This allows the creation of containers that share the host's user and group ID map, rather than receiving unique, non-overlapping ranges. Consequently, the isolation boundary between co-tenant containers and the host is weakened, potentially leading to unauthorized access or information disclosure within the shared environment.

Statement

Red Hat Product Security has determined that this vulnerability does not affect any currently supported Red Hat product. This assessment may evolve based on further analysis and discovery. For more information about this vulnerability and the products it affects, please see the linked references.

Understanding the Weakness (CWE)

Other

Technical Impact: Varies by Context

The impact of insecure defaults varies widely depending on the functionality that the product controls.

Frequently Asked Questions

Want to get errata notifications? Sign up here.