- Package:
- release.debian.org
- Source:
- release.debian.org
- Submitter:
- Mathias Gibbens
- Date:
- 2026-09-12 08:07:49 UTC
- Severity:
- normal
- Tags:
[ Reason ] Last week's release of Incus 7.4 included fixes for two moderate severity issues, CVE-2026-81500 and CVE-2026-81501. After discussion with the Security Team, these vulnerabilities won't receive their own DSA, but will be addressed via the upcoming point release. [ Impact ] Incus in trixie is currently vulnerable to CVE-2026-81500 and CVE-2026- 81501. [ Tests ] None -- both security issues are somewhat obscure edge cases, but the fixes have been in the stable release for a week now and no regressions have been reported upstream. [ Risks ] Minor/none -- two targeted fixes cherry-picked from the upstream git repo. [ Checklist ] [*] *all* changes are documented in the d/changelog [*] I reviewed all changes and I approve them [*] attach debdiff against the package in (old)stable [*] the issue is verified as fixed in unstable [ Changes ] Two security fixes as outlined above. Also updated d/changelog with missing CVEs that hadn't been assigned by GitHub when the previous release was uploaded. [ Other info ] The source debdiff is attached.
Control: tags -1 + confirmed Please go ahead. Regards, Adam
Uploaded, thanks! Mathias
package release.debian.org tags 1146498 = trixie pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian trixie. Thanks for your contribution! Upload details ============== Package: incus Version: 6.0.4-2+deb13u10 Explanation: fix path traversal issue [CVE-2026-81500]; fix insufficent access check issue [CVE-2026-81501]
package release.debian.org tags 1146498 = trixie pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian trixie. Thanks for your contribution! Upload details ============== Package: incus Version: 6.0.4-2+deb13u10 Explanation: fix path traversal issue [CVE-2026-81500]; fix insufficent access check issue [CVE-2026-81501]
This update was released as part of 13.7.