Incus is a system container and virtual machine manager. Prior to version 7.0.0, uploads of large amount of data by authenticated users can run the Incus server out of disk space, potentially taking down the host system. The impact here is limited for anyone using storage.images_volume and storage.backups_volume as those users will have large uploads be stored on those volumes rather than directly on the host filesystem. This is the default behavior on IncusOS. This issue has been patched in version 7.0.0.
References
| Link | Resource |
|---|---|
| https://github.com/lxc/incus/releases/tag/v7.0.0 | Patch Product |
| https://github.com/lxc/incus/security/advisories/GHSA-98vh-x9cx-9cfp | Exploit Vendor Advisory |
| https://github.com/lxc/incus/security/advisories/GHSA-98vh-x9cx-9cfp | Exploit Vendor Advisory |
Configurations
History
07 May 2026, 19:50
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/lxc/incus/releases/tag/v7.0.0 - Patch, Product | |
| References | () https://github.com/lxc/incus/security/advisories/GHSA-98vh-x9cx-9cfp - Exploit, Vendor Advisory | |
| CPE | cpe:2.3:a:linuxcontainers:incus:*:*:*:*:*:*:*:* | |
| First Time |
Linuxcontainers
Linuxcontainers incus |
07 May 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-07 14:16
Updated : 2026-05-07 19:50
NVD link : CVE-2026-41685
Mitre link : CVE-2026-41685
CVE.ORG link : CVE-2026-41685
JSON object : View
Products Affected
linuxcontainers
- incus
CWE
CWE-770
Allocation of Resources Without Limits or Throttling
