Incus is a system container and virtual machine manager. Prior to version 7.0.0, uploads of large amount of data by authenticated users can run the Incus server out of disk space, potentially taking down the host system. The impact here is limited for anyone using storage.images_volume and storage.backups_volume as those users will have large uploads be stored on those volumes rather than directly on the host filesystem. This is the default behavior on IncusOS. This issue has been patched in version 7.0.0.
Project Subscriptions
No data.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-6244-1 | incus security update |
Debian DSA |
DSA-6247-1 | lxd security update |
Github GHSA |
GHSA-98vh-x9cx-9cfp | Incus is affected by unbounded binary import disk exhaustion |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 07 May 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Incus is a system container and virtual machine manager. Prior to version 7.0.0, uploads of large amount of data by authenticated users can run the Incus server out of disk space, potentially taking down the host system. The impact here is limited for anyone using storage.images_volume and storage.backups_volume as those users will have large uploads be stored on those volumes rather than directly on the host filesystem. This is the default behavior on IncusOS. This issue has been patched in version 7.0.0. | |
| Title | Incus: Unbounded binary import disk exhaustion | |
| Weaknesses | CWE-770 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-07T13:50:17.247Z
Reserved: 2026-04-22T03:53:24.406Z
Link: CVE-2026-41685
No data.
Status : Received
Published: 2026-05-07T14:16:03.500
Modified: 2026-05-07T14:16:03.500
Link: CVE-2026-41685
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
Github GHSA