CVE-2026-33711 affects Incus, a system container and virtual machine manager, specifically versions prior to 6.23.0. A local attacker can exploit predictable temporary file paths used for VM screenshots by creating symlinks. This vulnerability, rated High (CVSS 7.8), allows an attacker with local access and low privileges to potentially cause denial of service, truncate arbitrary files, or achieve local privilege escalation on systems where the Linux kernel's protected_symlinks feature is disabled. While the vulnerability has garnered some community discussion, there is currently no evidence of active exploitation, nor are public exploit codes available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.23.0CPE matchmatch criteria | cpe:2.3:a:linuxcontainers:incus:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.