We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
Incus is a system container and virtual machine manager. When using an ACL on a device connected to a bridge, Incus version 6.12 and 6.13 generates nftables rules for local services (DHCP, DNS...) that partially bypass security options `security.mac_filtering`, `security.ipv4_filtering` and `security.ipv6_filtering`. This can lead to DHCP pool exhaustion and opens the door for other attacks. A patch is available at commit 2516fb19ad8428454cb4edfe70c0a5f0dc1da214.
Reserved 2025-06-20 | Published 2025-06-25 | Updated 2025-06-25 | Assigner GitHub_MCWE-770: Allocation of Resources Without Limits or Throttling
github.com/lxc/incus/security/advisories/GHSA-9q7c-qmhm-jv86
github.com/...ommit/2516fb19ad8428454cb4edfe70c0a5f0dc1da214
github.com/...ommit/a7c33301738aede3c035063e973b1d885d9bac7c
Support options