CVE-2026-40197Disclosure(linuxcontainers / incus)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the storage volume import logic allows an authenticated user with access to the storage volume feature to cause the Incus daemon to crash. The custom volume backup import subsystem contains a nil-pointer dereference vulnerability during import operations. In the snapshot import loop, the daemon iterates over entries from `srcBackup.Config.VolumeSnapshots` and assumes that each slice element is initialized, then dereferences fields such as `Name`, `Config`, `Description`, `CreatedAt`, and `ExpiresAt` without first validating the element itself. Because the yaml unmarshaler accepts explicit null array elements from an attacker-controlled index.yaml and converts them into nil pointers inside the slice, an attacker can supply a backup archive containing a null entry in the volume_snapshots array. This causes a nil-pointer dereference during custom volume import and terminates the daemon, resulting in denial of service on the affected node. Repeated use of this issue can be used to keep Incus offline, causing a denial of service. This issue is fixed in version 7.0.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-476

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • incus

Threat summary

  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-05-07); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Products
incus

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-05-04: 1Mentions · 2026-05-07: 2Mentions · 2026-06-26: 1Technical Details · 2026-05-04: 1Technical Details · 2026-05-07: 2Technical Details · 2026-06-26: 105-0405-0706-26
Signal classification2 categories
Disclosure
250.0%
General
250.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-041
Disclosure1
2026-05-072
Disclosure1General1
2026-06-261
General1
Full discourse4 posts
  • DailyCVE@dailycve
    General

    🟠 Incus daemon, Nil-Pointer Dereference, #CVE-2026-40197 (Medium) -DC-Jun2026-687 https://dailycve.com/incus-daemon-nil-pointer-dereference-cve-2026-40197-medium-dc-jun2026-687/

    Post summary

    The post announces CVE-2026-40197, identifies it as a nil-pointer dereference in the Incus daemon with Medium severity, and links to a dailycve article, but provides no evidence of exploitation, patches, or detailed technical data.

    0001036
    216 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-40197 Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the storage volume import logic allows an authenticated… https://www.cve.org/CVERecord?id=CVE-2026-40197

    Post summary

    The post references CVE-2026-40197 and notes a missing validation issue in Incus before version 7.0.0, but provides no PoC, exploit, or mitigation information.

    0000062
    57.4K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-40197 Denial of Service via Nil-Pointer Dereference in Incus Storage Volume Import https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40197

    Post summary

    The post announces CVE‑2026‑40197, a NULL‑pointer dereference that causes a denial of service in Incus Storage Volume Import, providing technical details but no proof‑of‑concept, exploit, or patch information.

    0000042
    4.0K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🟠 Incus, Nil Pointer Dereference, #CVE-2026-40197 (Medium) https://dailycve.com/incus-nil-pointer-dereference-cve-2026-40197-medium/

    Post summary

    The post announces the discovery of a nil pointer dereference in Incus (CVE‑2026‑40197) with a medium severity rating, providing only basic vulnerability details.

    0000035
    191 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applinuxcontainersincus---

Explore more