๐Ÿ” CVE Alert

CVE-2026-48756

UNKNOWN 0.0

Incus: CreateCustomVolumeFromBackup nil-pointer dereference on volume_snapshots[*].expires_at (sibling-field variant of GHSA-r7w7)

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Incus is a system container and virtual machine manager. Prior to version 7.1.0, `(*backend).CreateCustomVolumeFromBackup` in `internal/server/storage/backend.go` contains an unguarded `*time.Time` dereference on the `ExpiresAt` field of every volume-snapshot entry in an imported custom-volume backup. An authenticated user with `can_create_storage_volumes` permission on any project can crash the `incusd` daemon by uploading a backup tarball whose `volume_snapshots[*].expires_at` field is absent. This is a sibling-field variant of GHSA-r7w7-mmxr-47r9 (CVE-2026-40197). Commit `985a1dedf9f3e7ba729c93b654905ed510de25c2` added `if s == nil` at the top of the loop body, but did not guard the adjacent `*snapshot.ExpiresAt` deref 19 lines later. Every other consumer of `Config.VolumeSnapshots[i].ExpiresAt` in this same file already gates the deref with a nil-check โ€” the asymmetric guard is the bug. Version 7.1.0 contains an updated patch.

CWE CWE-476
Vendor lxc
Product incus
Published Aug 21, 2026
Stay Ahead of the Next One

Get instant alerts for lxc incus

Be the first to know when new unknown vulnerabilities affecting lxc incus are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

lxc / incus
< 7.1.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/lxc/incus/security/advisories/GHSA-xhqx-mgh3-3h7q