Skip to content

Tighten storage pool permissions#2642

Merged
hallyn merged 2 commits intolxc:mainfrom
stgraber:main
Nov 10, 2025
Merged

Tighten storage pool permissions#2642
hallyn merged 2 commits intolxc:mainfrom
stgraber:main

Conversation

@stgraber
Copy link
Copy Markdown
Member

@stgraber stgraber commented Nov 9, 2025

Closes #2641

This corrects a local privilege escalation issue when unprivileged users are allowed access to Incus through incus-user. The report wasn't done through the normal security disclosure pipeline so is processed publicly as a bugfix and will be cherry-picked quickly into the most commonly used packages.

A CVE was requested for this through Github and an advisory will be pushed out once the paperwork comes through.

@hallyn hallyn enabled auto-merge November 10, 2025 00:16
@hallyn hallyn merged commit 63315c8 into lxc:main Nov 10, 2025
104 of 106 checks passed
tomponline added a commit to canonical/lxd that referenced this pull request Nov 10, 2025
tomponline added a commit to canonical/lxd that referenced this pull request Nov 11, 2025
tomponline added a commit to canonical/lxd that referenced this pull request Nov 11, 2025
tomponline added a commit to canonical/lxd that referenced this pull request Nov 11, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

Local privilege escalation: a local unprivileged user in a restricted project may obtain host root privileges under certain conditions.

2 participants