CVE Explorer
CVE-2026-40197
Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the storage volume import logic allows an authenticated user with access to the storage volume feature to cause the Incus daemon to crash. The custom volume backup import subsystem contains a nil-pointer dereference vulnerability during import operations. In the snapshot import loop, the daemon iterates over entries from `srcBackup.Config.VolumeSnapshots` and assumes that each slice ele
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"incus","vendor":"lxc","versions":[{"status":"affected","version":"< 7.0.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:4b3eac85fac51b7efe3d03027859761af5cf98184e4acf54618cb0d908477b7a · sha256:bbe5abff596c9d3c… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":7.1,"baseSeverity":"HIGH","privilegesRequired":"LOW","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:4b3eac85fac51b7efe3d03027859761af5cf98184e4acf54618cb0d908477b7a · sha256:bbe5abff596c9d3c… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-476","description":"CWE-476: NULL Pointer Dereference","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:4b3eac85fac51b7efe3d03027859761af5cf98184e4acf54618cb0d908477b7a · sha256:bbe5abff596c9d3c… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"name":"https://github.com/lxc/incus/security/advisories/GHSA-r7w7-mmxr-47r9","tags":["x_refsource_CONFIRM"],"url":"https://github.com/lxc/incus/security/advisories/GHSA-r7w7-mmxr-47r9"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:4b3eac85fac51b7efe3d03027859761af5cf98184e4acf54618cb0d908477b7a · sha256:bbe5abff596c9d3c… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.