Description
Incus is a system container and virtual machine manager. Prior to version 6.23.0, a lack of validation of the image fingerprint when downloading from simplestreams image servers opens the door to image cache poisoning and under very narrow circumstances exposes other tenants to running attacker controlled images rather than the expected one. Version 6.23.0 patches the issue.
INFO
Published Date :
2026-03-26T22:32:13.733Z
Last Modified :
2026-03-26T22:32:13.733Z
Source :
GitHub_M
AFFECTED PRODUCTS
The following products are affected by CVE-2026-33542 vulnerability.
| Vendors | Products |
|---|---|
| Lxc |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2026-33542.
CVSS Vulnerability Scoring System
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact