CVE-2026-48769

Description

A flaw was found in Incus, a container and virtual machine manager. A malicious image server can cause the Incus client to write files to arbitrary locations via a crafted response header, potentially leading to command execution as root.

Statement

Incus is not shipped in any Red Hat product. The community Fedora package is affected.

Mitigation

No mitigation is needed as Incus is not shipped in any Red Hat product.

Understanding the Weakness (CWE)

Integrity,Other

Technical Impact: Varies by Context; Unexpected State

Frequently Asked Questions

Want to get errata notifications? Sign up here.