๐Ÿ” CVE Alert

CVE-2026-48754

UNKNOWN 0.0

Incus: Nil-pointer dereference in createDependentVolumesFromBackup on disk.{Volume,VolumeSnapshots,Pool}

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Incus is a system container and virtual machine manager. Prior to version 7.1.0, `(*backend).createDependentVolumesFromBackup` in `internal/server/storage/backend.go` contains a cluster of unguarded pointer derefs on every dependent-volume entry's `VolumeSnapshots[i]`, `Volume`, and `Pool` sub-fields. An authenticated user with `can_create_instances` permission on any project can crash the `incusd` daemon by uploading an instance backup tarball whose `dependent_volumes[*]` block contains a nil snapshot pointer (or omits `volume:` / `pool:`). This is a sibling-field variant of the 2026-05-04 batch fix `d768f81c0a1d985f35ae56219519822b080bf5e3` ("Properly check dependent volumes on import"). That commit added `if disk == nil` at the top of the outer loop, but did not guard the four sub-pointer fields the loop body dereferences naked. Version 7.1.0 contains an updated patch.

CWE CWE-476
Vendor lxc
Product incus
Published Aug 21, 2026
Stay Ahead of the Next One

Get instant alerts for lxc incus

Be the first to know when new unknown vulnerabilities affecting lxc incus are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

lxc / incus
< 7.1.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/lxc/incus/security/advisories/GHSA-4xg6-52mh-fpw8