Debian Patches
Status for incus/7.0.1-5
| Patch | Description | Author | Forwarded | Bugs | Origin | Last update |
|---|---|---|---|---|---|---|
| 001-skip-TestConvertNetworkConfig.patch | lxc prior to version 4.0.12 had a logic bug in do_lxcapi_create() that returned success in error conditions. Since this is a very simple test, that didn’t actually matter, but now to properly pass would require the setting up of a user-specific lxc configuration and sub[u|g]id mappings, which is just too much effort for a small test.diff --git a/cmd/lxc-to-incus/main_migrate_test.go b/cmd/lxc-to-incus/main_migrate_test.go index 6fbff5fce..d3783b998 100644 |
Mathias Gibbens <gibmat@debian.org> | not-needed | |||
| 002-adjust-import-paths.patch | Adjust import paths to reflect Debian packagingdiff --git a/cmd/incusd/daemon.go b/cmd/incusd/daemon.go index caae61fd4..6ca3b1b5f 100644 |
Mathias Gibbens <gibmat@debian.org> | not-needed | |||
| 003-Compile-against-go-criu-v7.patch | Compile against go-criu v7 | Reinhard Tartler <siretart@tauware.de> | no | 2024-08-08 | ||
| 004-include-incusos-network-structs.patch | Incus now consumes the IncusOS network API and cli package. This causes a dependency loop, so extract the relevant structs needed by Incus.diff --git a/cmd/incus/admin_os.go b/cmd/incus/admin_os.go index 12a8baf06..35cb3385d 100644 |
Mathias Gibbens <gibmat@debian.org> | not-needed | |||
| 005-fix-x509keypairleaf.patch | Debian's reliance on GO111MODULE=off is causing generation of a pfx client certificate to crash. Set the x509keypairleaf GODEBUG environment variable to use modern behavior.diff --git a/cmd/incus/main.go b/cmd/incus/main.go index 26d1fb4e6..fff211f30 100644 |
Mathias Gibbens <gibmat@debian.org> | not-needed | |||
| 006-fix-net-http-mux.patch | Debian's reliance on GO111MODULE=off is causing net/http to revert to incompatible behavior when serving requests. Set the httpmuxgo GODEBUG environment variable to use modern behavior.diff --git a/cmd/incusd/main.go b/cmd/incusd/main.go index 9fab6b3be..825995b86 100644 |
Mathias Gibbens <gibmat@debian.org> | not-needed | |||
| 100-CVE-2026-62313.patch | incusd/project: Enforce isolated restriction when idmap key omitted restricted.containers.privilege=isolated only rejected an explicit security.idmap.isolated=false, but the key defaults to non-isolated when omitted. Require containers to explicitly enable isolation. This addresses CVE-2026-62313 |
Stéphane Graber <stgraber@stgraber.org> | no | 2026-07-24 | ||
| 101-CVE-2026-62867.patch | incusd/project: Restrict volume creation options in restricted projects A user in a restricted project could set block.create_options to inject arguments into the filesystem creation command run as root. Restrict such projects to the pool's configured default for that option. This addresses CVE-2026-62867 |
Stéphane Graber <stgraber@stgraber.org> | no | 2026-07-24 | ||
| 102-CVE-2026-62940.patch | incusd/instance: Enforce project restrictions on migration overrides The migration handler applied user-supplied config, device and profile overrides without any project restriction check, letting a restricted project set keys like security.privileged or raw.lxc. This addresses CVE-2026-62940 |
Stéphane Graber <stgraber@stgraber.org> | no | 2026-07-24 | ||
| 103-CVE-2026-62941.patch | incusd/instances: Re-check restrictions after copy config merge The source instance's config is merged into the request only after the initial project restriction check, letting a cross-project copy carry restricted keys into the target project. Re-check the merged config. This addresses CVE-2026-62941 |
Stéphane Graber <stgraber@stgraber.org> | no | 2026-07-24 | ||
| 104-CVE-2026-63125.patch | incusd/storage: Confine backup.yaml write to instance root This addresses CVE-2026-63125 |
Stéphane Graber <stgraber@stgraber.org> | no | 2026-07-24 | ||
| 105-CVE-2026-63343.patch | incusd/instance: Confine metadata.yaml access to instance root This addresses CVE-2026-63343 |
Stéphane Graber <stgraber@stgraber.org> | no | 2026-07-24 | ||
| 106-GHSA-26gp-p5fw-3r2h.patch | incusd/instances: Validate instance name on backup import This addresses GHSA-26gp-p5fw-3r2h (CVE pending) |
Stéphane Graber <stgraber@stgraber.org> | no | 2026-07-24 | ||
| 107-GHSA-4qxq-p5hm-3q3p.patch | incusd/instance/qemu: Confine template access to instance root The template traversal guard from CVE-2026-48752 was only applied to the LXC driver. Apply the same checks to the QEMU driver. This addresses GHSA-4qxq-p5hm-3q3p (CVE pending) |
Stéphane Graber <stgraber@stgraber.org> | no | 2026-07-24 | ||
| 108-GHSA-67qw-68v3-36h6.patch | incusd/storage: Validate volume name on ISO and backup import This addresses GHSA-67qw-68v3-36h6 (CVE pending) |
Stéphane Graber <stgraber@stgraber.org> | no | 2026-07-24 | ||
| 109-GHSA-6v6x-387m-rj4w.patch | incusd: Expand network address set project for authorization The project expansion used for authorization had no branch for network address sets, so their access checks ran against the requested project rather than the effective one, letting a restricted project act on the default project's address sets. This addresses GHSA-6v6x-387m-rj4w (CVE pending) |
Stéphane Graber <stgraber@stgraber.org> | no | 2026-07-24 | ||
| 110-GHSA-7fj9-65v4-rp7h.patch | incusd/instance: Confine OCI network writes to instance root Also rejects line breaks in the oci.dns.domain and oci.dns.search values which are written to the generated resolv.conf. This addresses GHSA-7fj9-65v4-rp7h (CVE pending) |
Stéphane Graber <stgraber@stgraber.org> | no | 2026-07-24 | ||
| 111-GHSA-m3j6-p3v3-qmjv.patch | internal/instance: Prevent line breaks in NVIDIA config values This addresses GHSA-m3j6-p3v3-qmjv (CVE pending) |
Stéphane Graber <stgraber@stgraber.org> | no | 2026-07-24 | ||
| 112-GHSA-p2v3-6wvc-cv3p.patch | incusd/images: Validate image fingerprint for all protocols The fingerprint validation added for CVE-2026-48769 was only applied to the direct protocol. Validate it for all protocols and re-check after it is taken from the remote server's response. This addresses GHSA-p2v3-6wvc-cv3p (CVE pending) |
Stéphane Graber <stgraber@stgraber.org> | no | 2026-07-24 | ||
| 113-incus-7.3-fixes.patch | [PATCH 14/17] incusd/instance: Fix NVIDIA require.cuda and require.driver handling The condition was inverted, so a configured value was silently dropped while an empty value wrote an empty environment variable. Only write the variable when a value is set. |
Stéphane Graber <stgraber@stgraber.org> | no | 2026-07-24 | ||
| 114-CVE-2026-81500.patch | client/images: Prevent path traversal in downloaded image name The local filename for an exported image came from server-controlled data (Content-Disposition for unified images, the simplestreams index path) and was joined with the target directory. Basename it. This addresses GHSA-9pqw-c7m4-xvg7 (CVE pending) |
Stéphane Graber <stgraber@stgraber.org> | no | 2026-08-23 | ||
| 115-CVE-2026-81501.patch | incusd/images: Check access before reusing cross-project image imageDownload reused an image from another project without checking the caller could view it, letting a client that knew a private fingerprint import it. Only reuse it directly when public or viewable, otherwise download it (proving access) and dedupe against the on-disk copy. This addresses GHSA-c6wx-8679-hpr9 (CVE pending) |
Stéphane Graber <stgraber@stgraber.org> | no | 2026-08-23 | ||
| 116-cherry-pick-incusd-apparmor-rsync-destination-ancestors.patch | incusd/apparmor/rsync: Allow reading destination ancestors Closes #3968 |
Stéphane Graber <stgraber@stgraber.org> | yes | upstream | upstream, https://github.com/lxc/incus/commit/4846f45b56ffb4d8989823b63cb8703a51d2ae81 | 2026-09-15 |
| 117-cherry-pick-rsync-xattrs-transfer.patch | incusd/rsync: Only transfer xattrs settable without CAP_SYS_ADMIN Restrict xattrs to user.* and security.capability on the receiver so rsync doesn't fail on trusted.* or other security.* xattrs, which the AppArmor profile rightly prevents it from setting. Closes #3963 |
Stéphane Graber <stgraber@stgraber.org> | no | 2026-09-07 | ||
| 118-cherry-pick-concurrent-console.patch | [PATCH 1/2] incusd/instance/qmp: Handle ringbuf-read racing a chardev swap | Stéphane Graber <stgraber@stgraber.org> | no | 2026-09-10 | ||
| 119-GHSA-4cph-ccqv-hm3c.patch | incusd/project: Restrict volume options on update and copy The block.create_options restriction only covered direct volume creation. Apply it to volume updates and to the effective config of volumes created or refreshed from a copy, which fall back to the source volume's config. This addresses GHSA-4cph-ccqv-hm3c (CVE pending) |
Stéphane Graber <stgraber@stgraber.org> | no | 2026-09-15 | ||
| 120-GHSA-hpjh-q53p-f27r.patch | incusd/storage: Validate dependent volume names on backup import This addresses GHSA-hpjh-q53p-f27r (CVE pending) |
Stéphane Graber <stgraber@stgraber.org> | no | 2026-09-03 | ||
| 121-GHSA-579w-c4rw-c8q3.patch | incusd: Don't follow symlinks when receiving migration data The migration source controls the rsync and btrfs streams and can plant a symlink, such as rootfs pointing at /, then write through it while the transfer is still running, before the post-transfer symlink check. Bind-mount the receive path with nosymfollow for the duration of the receive and refuse a block volume file that was replaced by a symlink. This addresses GHSA-579w-c4rw-c8q3 (CVE pending) |
Stéphane Graber <stgraber@stgraber.org> | no | 2026-08-28 | ||
| 122-GHSA-x8gj-2q73-qr6j.patch | incusd/storage/buckets: Require can_edit to read bucket keys Bucket keys carry the S3 secret key, so reading them shouldn't be covered by the read-only access restricted clients get to resources in the default project. This addresses GHSA-x8gj-2q73-qr6j (CVE pending) |
Stéphane Graber <stgraber@stgraber.org> | no | 2026-09-15 | ||
| 123-GHSA-mmj7-8rgf-mx2h.patch | incusd/storage/s3: Require x-amz-* headers to be signed Headers such as X-Amz-Copy-Source change how a request is handled, so any x-amz-* header present on the request must be covered by the signature, as AWS S3 does. SigV2 now includes them in the string to sign. This addresses GHSA-mmj7-8rgf-mx2h (CVE pending) |
Stéphane Graber <stgraber@stgraber.org> | no | 2026-09-09 | ||
| 124-GHSA-jh4v-j34r-2mgh.patch | incusd/storage: Treat volume creation with a source as a copy The source volume access check added for CVE-2026-55621 only covers requests with an explicit "copy" source type, but a request with an empty type and a source name reaches the same copy code path without it. Normalize such requests to a copy before dispatching. This addresses GHSA-jh4v-j34r-2mgh (CVE pending) |
Stéphane Graber <stgraber@stgraber.org> | no | 2026-08-29 | ||
| 125-GHSA-mfwv-x733-9446.patch | incusd/operations: Check project access on operation get and wait The single operation GET and wait endpoints rendered any operation to any trusted client, regardless of the project it belongs to. Apply the same can_view_operations check as the operation listing. Waiting with a valid operation secret is unchanged so untrusted remote servers can still follow operations they were handed. This addresses GHSA-mfwv-x733-9446 (CVE pending) |
Stéphane Graber <stgraber@stgraber.org> | no | 2026-09-12 | ||
| 126-GHSA-wfvq-qh87-gm4j.patch | incus/file: Contain recursive pull symlinks A malicious incus-agent in a VM can return a directory listing with a duplicate entry and a stateful Lstat so that a single "incus file pull -r" plants a symlink then writes through it on the second visit, escaping the target directory. Track symlinks created during the transfer and replace them rather than write through or recurse into them. This addresses GHSA-wfvq-qh87-gm4j (CVE pending) |
Stéphane Graber <stgraber@stgraber.org> | no | 2026-08-27 | ||
| 127-GHSA-443p-7392-h4v2.patch | incusd/instances: Check project restrictions on clustered refresh The clustered migration refresh short-circuit skipped the project checks, letting a restricted project pull from an arbitrary remote. This addresses GHSA-443p-7392-h4v2 (CVE pending) |
Stéphane Graber <stgraber@stgraber.org> | no | 2026-09-23 | ||
| 128-GHSA-h85r-gjgx-g2rv-GHSA-27q7-qwhm-c34p.patch | incusd/storage/drivers: Confine btrfs subvolume paths BTRFSSubVolume.Path from a backup optimized header or a migration header was joined to the volume mount path and passed to root-run os.Remove/os.Rename/property-set without any containment, letting a crafted ../ escape the pool. Validate every path at each decode site. This addresses GHSA-h85r-gjgx-g2rv and GHSA-27q7-qwhm-c34p (CVEs pending) |
Stéphane Graber <stgraber@stgraber.org> | no | 2026-09-01 |
All known versions for source package 'incus'
- 7.5.1-1~exp1 (experimental)
- 7.0.1-5 (sid)
- 7.0.1-4 (forky)
- 7.0.1-3~bpo13+1 (trixie-backports)
- 6.0.4-2+deb13u11 (trixie-security, trixie-proposed-updates)
- 6.0.4-2+deb13u10 (trixie)
- 6.0.4-2+deb13u7~bpo12+1 (bookworm-backports)
