Affected by GO-2025-4115
and 21 other vulnerabilities
GO-2025-4115: Incus vulnerable to local privilege escalation through custom storage volumes in github.com/lxc/incus
GO-2026-4357: Incus container image templating arbitrary host file read and write in github.com/lxc/incus
GO-2026-4359: Incus container environment configuration newline injection in github.com/lxc/incus
GO-2026-5127: Incus Vulnerable to Panic via Snapshot Bounds Check in github.com/lxc/incus
GO-2026-5168: Incus has Unbounded YAML Metadata Decode via Parsing in github.com/lxc/incus
GO-2026-5252: Incus has a Nil-Pointer Dereference Panic via Instance Backup Import (volume omitted) in github.com/lxc/incus
GO-2026-5254: Incus has Blind SSRF via Image Import Preflight HEAD in github.com/lxc/incus
GO-2026-5280: Incus is affected by unbounded binary import disk exhaustion in github.com/lxc/incus
GO-2026-5319: Incus has an OVN TLS Verification that Accepts Peer-Supplied Roots in github.com/lxc/incus
GO-2026-5384: Incus has Nil-Pointer Dereference via S3 Bucket Import in github.com/lxc/incus
GO-2026-5397: Incus has a Nil-Pointer Dereference Panic via Bucket Metadata in github.com/lxc/incus
GO-2026-5612: Incus has a Nil-Pointer Dereference via Custom Volume Import in github.com/lxc/incus
GO-2026-5742: Incus has Nil Dereferences on Restore via Malformed YAML in github.com/lxc/incus
GO-2026-5798: Incus has an arbitrary file read+write on host via rootfs/ symlink in malicious image in github.com/lxc/incus
GO-2026-5799: Incus has a restricted project bypass leading to arbitrary command execution in github.com/lxc/incus
GO-2026-5800: Incus: Nil-pointer dereference in createDependentVolumesFromBackup on disk.{Volume,VolumeSnapshots,Pool} in github.com/lxc/incus
GO-2026-5801: Incus has an arbitrary file write on host via `exec-output` symlink in crafted image in github.com/lxc/incus
GO-2026-5802: Incus has an arbitrary file write via path traversal in S3 multipart upload in github.com/lxc/incus
GO-2026-5803: Incus has arbitrary file read+write on host via templates/ symlink in malicious image in github.com/lxc/incus
GO-2026-5806: Incus has an arbitrary file write on its client due to trusted image hash in github.com/lxc/incus
GO-2026-5808: Incus has an argument injection in backup compression algorithm leading to AFW and ACE in github.com/lxc/incus
GO-2026-5810: Incus: CreateCustomVolumeFromBackup nil-pointer dereference on volume_snapshots[*].expires_at (sibling-field variant of GHSA-r7w7) in github.com/lxc/incus
GetArchitectureFirmwarePairs creates an array of FirmwarePair for a
specific host architecture. If the environment variable INCUS_EDK2_PATH
has been set it will override the default installation path when
constructing Code & Vars paths.
GetArchitectureFirmwarePairsForUsage creates an array of FirmwarePair
for a specific host architecture and usage combination. If the
environment variable INCUS_EDK2_PATH has been set it will override the
default installation path when constructing Code & Vars paths.
FirmwareUsage represents the situation in which a given firmware file will be used.
const (
// GENERIC is a generic EDK2 firmware. GENERIC FirmwareUsage = iota// SECUREBOOT is a UEFI Secure Boot enabled firmware. SECUREBOOT
// CSM is a firmware with the UEFI Compatibility Support Module enabled to boot BIOS-only operating systems. CSM
)