Multiple vulnerabilities have been found in incus, the worst of which could result in privilege escalation. Affected packages Package app-containers/incus on all architectures Affected versions < 7.0.1-r1 Unaffected versions >= 7.0.1-r1 Background Incus is a container and virtual machine manager. Description Multiple vulnerabilities have been discovered in Incus. Please review the CVE identifiers referenced below for details. Impact Please review the referenced CVE identifiers for details. Workaround There is no known workaround at this time. Resolution All Incus users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=app-containers/incus-7.0.1-r1" References CVE-2026-23953 CVE-2026-23954 CVE-2026-35527 CVE-2026-40195 CVE-2026-40197 CVE-2026-40243 CVE-2026-40251 CVE-2026-41647 CVE-2026-41648 CVE-2026-41684 CVE-2026-41685 CVE-2026-48749 CVE-2026-48750 CVE-2026-48751 CVE-2026-48752 CVE-2026-48755 CVE-2026-48769 CVE-2026-55621 CVE-2026-55622 GHSA-7f67-crqm-jgh7 GHSA-x6jc-phwx-hp32 Release date August 25, 2026 Latest revision August 25, 2026: 1 Severity high Exploitable local and remote Bugzilla entries 969235 974495 978133 980304
Multiple vulnerabilities in Incus, including high-severity flaws (CVSS up to 8.7), could lead to privilege escalation. Affected versions are Incus <= 6.0.5 and >= 6.1.0 < 6.21.0 for some CVEs, and < 7.0.0 for others. The resolution is to upgrade to Incus version 7.0.1-r1 or later, as no workaround is currently available.