Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Incus nil-pointer dereference in storage bucket import allows denial of service
Vulnerability Description
Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the storage bucket import logic allows an authenticated user with access to the storage bucket feature to cause the Incus daemon to crash. The vulnerability is present in the backup metadata handling logic, where the daemon processes the index.yaml file from an imported archive and accesses members of the parsed backup configuration without first verifying that the configuration object was initialized. A malicious or malformed index.yaml that omits the config block causes a nil-pointer dereference during bucket import operations and terminates the daemon. Repeated use of this issue can be used to keep Incus offline, causing a denial of service. This issue is fixed in version 7.0.0.
CVSS Information
N/A
Vulnerability Type
空指针解引用
Vulnerability Title
Incus 代码问题漏洞
Vulnerability Description
Incus是LXC开源的一个系统容器和虚拟机管理器。 Incus 7.0.0之前版本存在代码问题漏洞,该漏洞源于存储桶导入逻辑中缺少验证逻辑,可能导致经过身份验证的用户通过恶意或格式错误的index.yaml文件导致空指针取消引用,使守护进程崩溃。
CVSS Information
N/A
Vulnerability Type
N/A