logo

Debian LXD and Incus Command Execution Bypass Vulnerabilities Disclosed

ID: c96d2870-45c2-5c46-a727-a846614d1650

STIX ID: report--c96d2870-45c2-5c46-a727-a846614d1650

Feed Name: ThreatCluster

Threat Score
70/100

Date Published: 2026-06-28

Date Updated: 2026-07-02

...
...

Debian published security advisories for critical command-execution bypass vulnerabilities in LXD and Incus, and provided patched package versions (LXD 5.0.2+git20231211.1364ae4-9+deb13u7 and Incus 6.0.4-2+deb13u8). Users of the stable (trixie) distribution are urged to upgrade immediately to mitigate potential unauthorized command execution; the advisories note the issues are critical but do not list CVEs or evidence of active exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.