Linuxsecurity Fedora Incus 6.23 Security Update Addresses Multiple Vulnerabilities
Article Content
- •Fedora released a security update for Incus 6.23 on April 20, 2026.
- •The update addresses multiple CVEs, including CVE-2025-58183 and CVE-2026-23954.
- •Users are advised to update their systems to mitigate potential vulnerabilities.
On April 20, 2026, Fedora released a security update for Incus 6.23, a container hypervisor based on LXC. The update removes the incus dependency from incus-agent and addresses several vulnerabilities. Notable CVEs include CVE-2025-58183, which involves unbounded allocation when parsing GNU sparse maps, and CVE-2026-23954, which allows arbitrary host file read and write through container image templating. Other vulnerabilities include CVE-2025-69725, an open redirect issue, and CVE-2026-23953, which involves newline injection in container environment configuration. The update is crucial for users of Fedora 42 and 43, as it mitigates potential exploits that could affect container management and security. Users are advised to apply the update using the 'dnf' package manager. The advisory emphasizes the importance of keeping systems updated to prevent exploitation of these vulnerabilities.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2025-47910 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
Critical Authentication Bypass in Rejetto HFS Exploited Within 24 Hours Anthropic's Mythos model identified a critical authentication bypass in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, allowing remote code execution. Discovered by Horizon3 researcher Zach Hanley, the flaw was revealed on September 27, 2026, and exploitation began within 24 hours, with attacks traced to…