Skip to content
Fedora Incus 6.23 Security Update Addresses Multiple Vulnerabilities

Fedora Incus 6.23 Security Update Addresses Multiple Vulnerabilities

First seen 20 Apr 2026, 05:43 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •April 21, 2026 at 04:59 UTC
  • •Fedora released a security update for Incus 6.23 on April 20, 2026.
  • •The update addresses multiple CVEs, including CVE-2025-58183 and CVE-2026-23954.
  • •Users are advised to update their systems to mitigate potential vulnerabilities.

On April 20, 2026, Fedora released a security update for Incus 6.23, a container hypervisor based on LXC. The update removes the incus dependency from incus-agent and addresses several vulnerabilities. Notable CVEs include CVE-2025-58183, which involves unbounded allocation when parsing GNU sparse maps, and CVE-2026-23954, which allows arbitrary host file read and write through container image templating. Other vulnerabilities include CVE-2025-69725, an open redirect issue, and CVE-2026-23953, which involves newline injection in container environment configuration. The update is crucial for users of Fedora 42 and 43, as it mitigates potential exploits that could affect container management and security. Users are advised to apply the update using the 'dnf' package manager. The advisory emphasizes the importance of keeping systems updated to prevent exploitation of these vulnerabilities.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 170d ago How this analysis works

Timeline

2025-09-22
CVE-2025-47910 published
2025-10-29
CVE-2025-58183 published
2026-01-22
CVE-2026-23953 published
2026-01-22
CVE-2026-23954 published
2026-02-19
CVE-2025-69725 published
2026-04-20
Fedora releases security update for Incus 6.23

More articles in this cluster (2)

Following this threat?

Track CVE-2025-47910 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed