Debian LXD and Incus Command Execution Bypass Vulnerabilities Disclosed

Debian LXD and Incus Command Execution Bypass Vulnerabilities Disclosed

First seen 28 Jun 2026, 16:33 UTC Linuxsecurity 70% similarity 72.6
Share:

Article Content

Browse articles
ThreatCluster

Debian has issued security advisories for critical command execution bypass vulnerabilities in LXD and Incus. The vulnerabilities were addressed in LXD version 5.0.2+git20231211.1364ae4-9+deb13u7 and Incus version 6.0.4-2+deb13u8. Users of the stable distribution (trixie) are urged to upgrade their packages to mitigate potential exploitation. The vulnerabilities could allow unauthorized command execution, posing a significant risk to systems utilizing these tools. The advisories recommend immediate action to apply the updates. No specific CVEs were mentioned in the articles, but the issues are classified as critical. The security status of both LXD and Incus can be tracked through Debian's security tracker pages.

Key Points: • Critical command execution bypass vulnerabilities found in Debian's LXD and Incus. • Users are advised to upgrade to LXD 5.0.2+git20231211.1364ae4-9+deb13u7 and Incus 6.0.4-2+deb13u8. • Immediate action is recommended to prevent potential unauthorized command execution.

ThreatCluster AI

Timeline

2026-06-26
Debian Incus vulnerability disclosed
Debian announced a critical command execution bypass vulnerability in Incus, fixed in version 6.0.4-2+deb13u8.
Linuxsecurity
2026-06-28
Debian LXD vulnerability disclosed
Debian issued a security advisory for a critical command execution bypass in LXD, addressed in version 5.0.2+git20231211.1364ae4-9+deb13u7.
Linuxsecurity

Community

Browse all →