Horizon Alert
Summary of the vulnerability and why it matters
A vulnerability exists in Incus, a system container and virtual machine manager, that could allow a user with limited privileges to execute arbitrary code as root on the host system. This could occur if a specially crafted image is used, causing the system to follow a symbolic link during the backup process. The issue has been addressed in version 7.3.0.
- Limited users could run unauthorized code.
- Matters for system integrity and control.
- Confirm if Incus is in use and relevant.
Attack Path
How an attacker could exploit the issue
An unprivileged user within Incus, a system container and virtual machine manager, can craft a special image containing a symbolic link. This link, when used in the backup process by the root daemon, allows arbitrary code execution on the host system, potentially granting the attacker root privileges.
- Requires unprivileged user access.
- Triggered by a crafted image backup.
- Allows arbitrary code execution as root.
Live Threat
Current exploitation, exposure, and threat context
When supported by the advisory, an unprivileged user with specific permissions within Incus could execute arbitrary code as root on the host system. This is possible when a crafted image is used to create a symbolic link to a sensitive host file, which the Incus daemon then follows during the backup process.
- Host system files could be exposed.
- Backup process may follow symlinks.
- Arbitrary code execution as root.
Operational Fix
Recommended remediation, mitigation, and detection steps
This vulnerability impacts Incus, a system container and virtual machine manager. The immediate priority is for infrastructure or platform teams to identify all Incus deployments, assess their exposure, and determine business criticality to prioritize remediation efforts with the accountable owner.
- Identify Incus deployments and ownership.
- Verify instance reachability and impact.
- Plan remediation based on risk.