CVE-2026-33743Disclosure(linuxcontainers / incus)

LOWCVSS 6.5 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Incus is a system container and virtual machine manager. Prior to version 6.23.0, a specially crafted storage bucket backup can be used by an user with access to Incus' storage bucket feature to crash the Incus daemon. Repeated use of this attack can be used to keep the server offline causing a denial of service of the control plane API. This does not impact any running workload, existing containers and virtual machines will keep operating. Version 6.23.0 fixes the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-770

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • incus

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-05-04)
  • 3 total mentions across 2 days

Affected systems

Products
incus

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-27: 1Mentions · 2026-05-04: 2Technical Details · 2026-03-27: 1Technical Details · 2026-05-04: 203-2705-04
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-271
Disclosure1
2026-05-042
Disclosure1General1
Full discourse3 posts
  • DailyCVE@dailycve
    General

    🟠 Incus, Denial of Service (Unbounded Memory Allocation), #CVE-2026-33743 (Medium) https://dailycve.com/incus-denial-of-service-unbounded-memory-allocation-cve-2026-33743-medium/

    Post summary

    The post references CVE‑2026‑33743 for Incus, noting a medium‑severity denial‑of‑service vulnerability via unbounded memory allocation, but only provides a link without further exploitation or patch details.

    0000037
    191 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 Incus, Nil-Pointer Dereference, #CVE-2026-33743 (High) https://dailycve.com/incus-nil-pointer-dereference-cve-2026-33743-high/

    Post summary

    The post announces a newly disclosed nil‑pointer dereference vulnerability in Incus (CVE‑2026‑33743) with high severity, but no PoC, exploit or patch information is provided.

    0000026
    191 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33743 Incus is a system container and virtual machine manager. Prior to version 6.23.0, a specially crafted storage bucket backup can be used by an user with access to Incu… https://www.cve.org/CVERecord?id=CVE-2026-33743

    Post summary

    The message announces CVE-2026-33743, explaining that a specially crafted storage bucket backup can be abused in Incus prior to v6.23.0, but it provides no PoC, exploit, or patch details.

    00000119
    56.9K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applinuxcontainersincus---

Explore more