CVE-2026-47753: CWE-476: NULL Pointer Dereference in lxc incus
Description
CVE-2026-47753 is a medium severity vulnerability in Incus, a system container and virtual machine manager. Prior to version 7.1.0, a nil-pointer dereference exists in the CreateInstanceFromBackup function within the storage backend. An authenticated user with permission to create instances can remotely trigger this by uploading a crafted backup tarball, causing the Incus daemon to panic and crash. This results in denial of service affecting all projects on the cluster member. Version 7.1.0 includes a patch that addresses this issue.
CVSS v4.0
Score 4.4medium
Affected software
lxc
incus
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability CVE-2026-47753 involves a NULL pointer dereference in the Incus daemon's internal server storage backend code, specifically in the CreateInstanceFromBackup method. This flaw can be triggered remotely by an authenticated user with instance creation permissions by uploading a malicious backup tarball. The resulting daemon panic causes a process crash and denial of service to all projects on the affected cluster member. The issue is related to missing guards on the Volume field of the backup/config.Config struct, which was overlooked in previous patches addressing similar adjacent fields. The vulnerability is fixed in Incus version 7.1.0.
Potential Impact
An authenticated user with permission to create instances can remotely cause the Incus daemon to crash by exploiting this NULL pointer dereference. This leads to denial of service for all projects on the affected cluster member, potentially disrupting container and virtual machine management operations.
Mitigation Recommendations
Upgrade Incus to version 7.1.0 or later, which contains the official patch addressing this NULL pointer dereference vulnerability. No other mitigation is required as the issue is fixed in this release.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-05-19T22:16:39.505Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a885f67acd9273b493f93ed
Added to database: 08/21/2026, 14:23:35 UTC
Last enriched: 09/11/2026, 02:47:26 UTC
Last updated: 10/05/2026, 06:48:16 UTC
Views: 72
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.