CVE-2026-23953 describes a newline injection vulnerability in Incus versions 6.20.0 and below, a system container and virtual machine manager. An authenticated user with container launch privileges can inject newlines into environment variables, manipulating lxc.conf to add arbitrary lifecycle hooks. This allows for arbitrary command execution on the host system. The vulnerability has a CVSS score of 8.7 (HIGH), indicating a network-adjacent attack vector with low complexity and high impact on confidentiality and integrity. There is no evidence of active exploitation, public exploit code, or inclusion in the KEV catalog, though it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 6.0.5CPE matchmatch criteria | cpe:2.3:a:linuxcontainers:incus:*:*:*:*:*:*:*:* | ||
>= 6.1.0, < 6.21.0CPE matchmatch criteria | cpe:2.3:a:linuxcontainers:incus:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.