← back
CVE-2026-33542

Incus does not verify combined fingerprint when downloading images from simplestreams servers

CVSS 5.7 MEDIUMEPSS 0.2%CWE-295
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.7EPSS 0.2%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
26 Mar 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Incus is a system container and virtual machine manager. Prior to version 6.23.0, a lack of validation of the image fingerprint when downloading from simplestreams image servers opens the door to image cache poisoning and under very narrow circumstances exposes other tenants to running attacker controlled images rather than the expected one. Version 6.23.0 patches the issue.
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:L/SI:H/SA:N/E:P
Affected products
lxc · incus

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →