Impact
The attack allows a user confined to a single project to override instance configuration during migration to another cluster node. This bypasses project boundary checks, enabling flag changes such as security.privileged or raw.lxc. As a consequence, the user can obtain root‑like privileges inside the container and, in the worst case, escape to the host. The flaw represents a missing authorization and a key‑override weakness, reflected by the CWE tags for missing authorization and authorization bypass through user‑controlled key, and is rated with a CVSS base score of 9.9, reflecting its critical impact.
Affected Systems
The issue affects the Incus container/VM manager provided by lxc:incus. All releases prior to 7.3.0 are vulnerable. Incus 7.3.0 and later contain the fix that enforces project restrictions during migration and sanitizes configuration overrides.
Risk and Exploitability
The risk is high due to the 9.9 CVSS score and the minimal EPSS figure (< 1 %), indicating a low yet non‑zero likelihood of exploitation. The vulnerability is not yet listed in the CISA KEV, so no confirmed public exploitation is known. Based on the description, it is inferred that an attacker must have a project‑level account with permission to migrate instances to another cluster member, which is a common scenario in multi‑tenant deployments. Despite the lack of a concrete exploitation statistic, the critical nature of the flaw strongly recommends immediate patching.
OpenCVE Enrichment
Debian DSA