CVE-2026-40195Disclosure(linuxcontainers / incus)

LOWCVSS 6.5 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the storage bucket import logic allows an authenticated user with access to the storage bucket feature to cause the Incus daemon to crash. The vulnerability is present in the backup metadata handling logic, where the daemon processes the index.yaml file from an imported archive and accesses members of the parsed backup configuration without first verifying that the configuration object was initialized. A malicious or malformed index.yaml that omits the config block causes a nil-pointer dereference during bucket import operations and terminates the daemon. Repeated use of this issue can be used to keep Incus offline, causing a denial of service. This issue is fixed in version 7.0.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-476

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • incus

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Products
incus

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-05-07: 2Technical Details · 2026-05-07: 205-07
Signal classification1 categories
Disclosure
2100.0%
Referenced assets3 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-40195 Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the storage bucket import logic allows an authenticated… https://www.cve.org/CVERecord?id=CVE-2026-40195

    Post summary

    The text announces CVE-2026-40195 for Incus before version 7.0.0, citing missing validation logic in the storage bucket import, and directs readers to the official CVE record.

    0000063
    57.4K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-40195 Denial of Service via Nil-Pointer Dereference in Incus Storage Bu... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40195 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The tweet announces CVE‑2026‑40195 as a denial‑of‑service flaw in Incus Storage, providing a brief technical description but no evidence of active exploitation, PoC, or patch information.

    0000037
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applinuxcontainersincus---

Explore more