CVE-2026-63125

9.9

LXC · Incus

An authenticated Incus user can achieve arbitrary code execution as root on the host by supplying a crafted image containing a symlink to a host file.

Executive summary

A critical vulnerability in LXC Incus allows an authenticated, project-confined user to escape their container environment and execute arbitrary code as root on the host system.

Vulnerability

This vulnerability involves improper link resolution, where the root daemon follows a symbolic link placed in a backup.yaml file within a crafted image. An authenticated user with limited privileges can leverage this flaw to perform unauthorized file operations on the host.

Business impact

The ability for a low-privileged user to gain root execution on the host represents a total compromise of the virtualization infrastructure. This allows an attacker to bypass all container isolation boundaries, potentially leading to complete data loss, unauthorized access to sensitive host configurations, and the installation of persistent backdoors. Given the CVSS score of 9.9, the risk to confidentiality, integrity, and availability is extreme.

Remediation

Immediate Action: Update all instances of LXC Incus to version 7.3.0 or later immediately to resolve the symlink following flaw.

Proactive Monitoring: Audit Incus logs for unusual image creation activity or unauthorized access attempts originating from non-admin project-confined identities.

Compensating Controls: Strictly enforce role-based access control policies to limit the number of users capable of creating images until the update is deployed.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The severity of this vulnerability necessitates immediate patching. Organizations should prioritize updating their Incus environments to 7.3.0 to neutralize the risk of host-level system compromise.

More LXC CVEs