#1146498 trixie-pu: package incus/6.0.4-2+deb13u10

#1146498#5
Date:
2026-09-02 16:53:55 UTC
From:
To:
[ Reason ]
Last week's release of Incus 7.4 included fixes for two moderate
severity issues, CVE-2026-81500 and CVE-2026-81501. After discussion
with the Security Team, these vulnerabilities won't receive their own
DSA, but will be addressed via the upcoming point release.

[ Impact ]
Incus in trixie is currently vulnerable to CVE-2026-81500 and CVE-2026-
81501.

[ Tests ]
None -- both security issues are somewhat obscure edge cases, but the
fixes have been in the stable release for a week now and no regressions
have been reported upstream.

[ Risks ]
Minor/none -- two targeted fixes cherry-picked from the upstream git
repo.

[ Checklist ]
  [*] *all* changes are documented in the d/changelog
  [*] I reviewed all changes and I approve them
  [*] attach debdiff against the package in (old)stable
  [*] the issue is verified as fixed in unstable

[ Changes ]
Two security fixes as outlined above. Also updated d/changelog with
missing CVEs that hadn't been assigned by GitHub when the previous
release was uploaded.

[ Other info ]
The source debdiff is attached.

#1146498#12
Date:
2026-09-04 13:28:37 UTC
From:
To:
Control: tags -1 + confirmed

Please go ahead.

Regards,

Adam

#1146498#19
Date:
2026-09-04 13:33:57 UTC
From:
To:
  Uploaded, thanks!

Mathias

#1146498#24
Date:
2026-09-05 15:20:14 UTC
From:
To:
package release.debian.org
tags 1146498 = trixie pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian trixie.

Thanks for your contribution!

Upload details
==============

Package: incus
Version: 6.0.4-2+deb13u10

Explanation: fix path traversal issue [CVE-2026-81500]; fix insufficent access check issue [CVE-2026-81501]

#1146498#29
Date:
2026-09-05 15:20:14 UTC
From:
To:
package release.debian.org
tags 1146498 = trixie pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian trixie.

Thanks for your contribution!

Upload details
==============

Package: incus
Version: 6.0.4-2+deb13u10

Explanation: fix path traversal issue [CVE-2026-81500]; fix insufficent access check issue [CVE-2026-81501]

#1146498#34
Date:
2026-09-12 08:05:41 UTC
From:
To:
This update was released as part of 13.7.