Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-6184-1 | incus security update |
Github GHSA |
GHSA-vg76-xmhg-j5x3 | Incus vulnerable to denial of source through crafted bucket backup file |
Mon, 30 Mar 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Linuxcontainers
Linuxcontainers incus |
|
| CPEs | cpe:2.3:a:linuxcontainers:incus:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Linuxcontainers
Linuxcontainers incus |
Fri, 27 Mar 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 27 Mar 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-1286 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Fri, 27 Mar 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Lxc
Lxc incus |
|
| Vendors & Products |
Lxc
Lxc incus |
Fri, 27 Mar 2026 04:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Incus is a system container and virtual machine manager. Prior to version 6.23.0, a specially crafted storage bucket backup can be used by an user with access to Incus' storage bucket feature to crash the Incus daemon. Repeated use of this attack can be used to keep the server offline causing a denial of service of the control plane API. This does not impact any running workload, existing containers and virtual machines will keep operating. Version 6.23.0 fixes the issue. | |
| Title | Incus vulnerable to denial of source through crafted bucket backup file | |
| Weaknesses | CWE-770 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-27T13:53:39.299Z
Reserved: 2026-03-23T17:34:57.561Z
Link: CVE-2026-33743
Updated: 2026-03-27T13:27:39.027Z
Status : Analyzed
Published: 2026-03-26T23:16:20.583
Modified: 2026-03-30T18:54:51.560
Link: CVE-2026-33743
OpenCVE Enrichment
Updated: 2026-03-31T20:01:24Z
Debian DSA
Github GHSA