Untriaged
Incus does not verify combined fingerprint when downloading images from simplestreams servers
Incus is a system container and virtual machine manager. Prior to version 6.23.0, a lack of validation of the image fingerprint when downloading from simplestreams image servers opens the door to image cache poisoning and under very narrow circumstances exposes other tenants to running attacker controlled images rather than the expected one. Version 6.23.0 patches the issue.
References
- https://github.com/lxc/incus/security/advisories/GHSA-p8mm-23gg-jc9r x_refsource_CONFIRM
Affected products
incus
- ==< 6.23.0
Matching in nixpkgs
pkgs.incus
Powerful system container and virtual machine manager
pkgs.incus-lts
Powerful system container and virtual machine manager
pkgs.incus-ui-canonical
Web user interface for Incus
pkgs.terraform-providers.incus
None
Package maintainers
-
@jnsgruk Jon Seager <jon@sgrs.uk>
-
@megheaiulian Meghea Iulian <iulian.meghea@gmail.com>
-
@adamcstephens Adam C. Stephens <happy.plan4249@valkor.net>
-
@mkg20001 Maciej Krüger <mkg20001+nix@gmail.com>
-
@aanderse Aaron Andersen <aaron@fosslib.net>