CVE-2025-64507

7.8 HIGH
Published: November 10, 2025 Modified: December 29, 2025

Description

Incus is a system container and virtual machine manager. An issue in versions prior to 6.0.6 and 6.19.0 affects any Incus user in an environment where an unprivileged user may have root access to a container with an attached custom storage volume that has the `security.shifted` property set to `true` as well as access to the host as an unprivileged user. The most common case for this would be systems using `incus-user` with the less privileged `incus` group to provide unprivileged users with an isolated restricted access to Incus. Such users may be able to create a custom storage volume with the necessary property (depending on kernel and filesystem support) and can then write a setuid binary from within the container which can be executed as an unprivileged user on the host to gain root privileges. A patch for this issue is expected in versions 6.0.6 and 6.19.0. As a workaround, permissions can be manually restricted until a patched version of Incus is deployed.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

CVSS v3.x Details

0.0 Low Medium High Critical 10.0
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
https://github.com/lxc/incus/issues/2641
Source: security-advisories@github.com
Exploit Issue Tracking Patch
https://github.com/lxc/incus/pull/2642
Source: security-advisories@github.com
Exploit Issue Tracking Patch
https://github.com/lxc/incus/security/advisories/GHSA-56mx-8g9f-5crf
Source: security-advisories@github.com
Exploit Vendor Advisory Patch
https://github.com/lxc/incus/issues/2641
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
Exploit Issue Tracking Patch

4 reference(s) from NVD

Quick Stats

CVSS v3 Score
7.8 / 10.0
EPSS (Exploit Probability)
0.0%
8th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

linuxcontainers