[SECURITY] [DSA 6212-1] incus security update To : debian-security-announce@lists.debian.org Subject : [SECURITY] [DSA 6212-1] incus security update From : Moritz Muehlenhoff < jmm@debian.org > Date : Wed, 15 Apr 2026 19:16:03 +0000 Message-id : < [🔎] ad_j8ypG1CZOUEJm@seger.debian.org > Reply-to : debian-security-announce-request@lists.debian.org -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-6212-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff April 15, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : incus CVE ID : CVE-2026-34178 CVE-2026-34179 Two security issues were discovered in Incus, a system container and virtual machine manager, which could result in restriction bypass or privilege escalation. For the stable distribution (trixie), these problems have been fixed in version 6.0.4-2+deb13u6. We recommend that you upgrade your incus packages. For the detailed security status of incus please refer to its security tracker page at: https://security-tracker.debian.org/tracker/incus Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmnf4xQACgkQEMKTtsN8 Tja9pw/+Mmcw02SGkoAm4X41PYEP2xxtSUVO/lenmWB6hibtP2IthuVAHF97/L79 xUzSkiziuubTuayjN8ETU5r0XDru3qbw1cHLItqcRg5FDs7LLPtO2cMs+OJVlZ30 remc3YfsJE1UR/2mGyuHxk/2TEoGqM+g9eGCiK2fvojVgdIKwl+uPm6uv5xHi5Vc lmSzYWZyFLLZ/Tr8viAUCmphKZ4pjLQCm7aZT7BJ3LYyNG29FZGAX/eq3dCs7P2u hodR/OmzGdCS33pewvjGVrDPVgQ+CYoHufy0H6dZUIqbxTfJr53EnS+Aje7/4ZIY 8mURksH6hRR0lc2fyj7i9V9ytJZ2oT/xLgkz64nbO6+JJV5NUWqMqRQkEXZV6Q6G CAHSDW+5W2IyUAliQEUU9askAEHR7wEbZi9d0Gnok20qsl3o8lEn8RhCZNQmogJf F+78QDOMi0ypoDVgYG0Okq/HNmIVU1wYlBC24ndjDgzMIm/SCvsRcoEZDszb2LQi jXlIIUyWp+D0duccPNCMCdf4wG9WZqh/QNq2iXfIsnLrrSfsABk85KH2QUYMGtgI DdXg8uqdlSypKR0RnwgYGBN/mdTsszFceEqPwMTtGgp8uCB3ey5mkUrz2Nf3C/3W FUbilfI3GGbWnVJaveAXPg3wyAc9oByu6099XC3ll13CvZWbdXY= =YR6J -----END PGP SIGNATURE----- Reply to: debian-security-announce@lists.debian.org Moritz Muehlenhoff (on-list) Moritz Muehlenhoff (off-list) Prev by Date: [SECURITY] [DSA 6211-1] thunderbird security update Next by Date: [SECURITY] [DSA 6213-1] lxd security update Previous by thread: [SECURITY] [DSA 6211-1] thunderbird security update Next by thread: [SECURITY] [DSA 6213-1] lxd security update Index(es): Date Thread
Two critical vulnerabilities (CVE-2026-34178 and CVE-2026-34179, both CVSS 9.1) in Incus could lead to restriction bypass or privilege escalation. The issues affect the Debian stable distribution (trixie) and are fixed in version 6.0.4-2+deb13u6. Users are advised to upgrade their incus packages immediately.