Impact
The vulnerability allows a specially crafted image or instance backup to read or create and write arbitrary files on the host before version 7.2.0, potentially enabling arbitrary command execution and compromising confidentiality, integrity, and availability. The weakness is classified as CWE-61 and CWE-73.
Affected Systems
Incus, the system container and virtual machine manager developed by LXC, is affected in all releases prior to version 7.2.0. Users running those older versions should upgrade to 7.2.0 or later, which contains a fix that removes the ability to use crafted images or backups to manipulate arbitrary host files.
Risk and Exploitability
The CVSS score of 9.9 indicates a very high severity. The vulnerability can be exploited by submitting a crafted image or backup to the Incus service, which could allow an attacker to read or modify host files and potentially execute commands. EPSS score is < 1%, indicating a very low but nonzero probability of exploitation, and the vulnerability is not listed in KEV. Based on the description, it is inferred that the vulnerability is exploitable by supplying a crafted image or backup to the Incus service, though the exact attack vector (local or remote) is not explicitly stated.
OpenCVE Enrichment
Debian DSA
Github GHSA