CyberRota Analysis
AI-GeneratedIncus versions prior to 7.3.0 are vulnerable due to a flaw in handling `metadata.yaml` symlinks, allowing authenticated users to read or overwrite arbitrary host files as root through the instance metadata API. This critical vulnerability poses a significant risk to system integrity and data confidentiality. Organizations using affected versions should prioritize upgrading to 7.3.0 or later to mitigate potential exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Incus is a system container and virtual machine manager. Prior to version 7.3.0, a malicious image containing a `metadata.yaml` symlink pointing to an arbitrary host path allows an authenticated Incus user to read or overwrite any file on the host as root via the instance metadata API. The `exec-output` and `templates/` paths were patched in a prior release using `Lstat` rejection and `os.OpenRoot` confinement; `metadata.yaml` was not included in either patch and remains exploitable. Version 7.3.0 patches the issue.