Alpine: multiple incus-feature packages: security update to 6.21.0-r0

high Tenable Cloud Security Plugin ID 436932

Description

There are packages installed that are affected by multiple vulnerabilities referenced in the following CVEs:

- Incus is a system container and virtual machine manager. In versions 6.20.0 and below, a user with the
ability to launch a container with a custom YAML configuration (e.g a member of the ‘incus’ group) can
create an environment variable containing newlines, which can be used to add additional configuration
items in the container’s lxc.conf due to newline injection. This can allow adding arbitrary lifecycle
hooks, ultimately resulting in arbitrary command execution on the host. Exploiting this issue on IncusOS
requires a slight modification of the payload to change to a different writable directory for the
validation step (e.g /tmp). This can be confirmed with a second container with /tmp mounted from the host
(A privileged action for validation only). A fix is planned for versions 6.0.6 and 6.21.0, but they have
not been released at the time of publication. (CVE-2026-23953)

- Incus is a system container and virtual machine manager. Versions 6.21.0 and below allow a user with the
ability to launch a container with a custom image (e.g a member of the ‘incus’ group) to use directory
traversal or symbolic links in the templating functionality to achieve host arbitrary file read, and host
arbitrary file write. This ultimately results in arbitrary command execution on the host. When using an
image with a metadata.yaml containing templates, both the source and target paths are not checked for
symbolic links or directory traversal. This can also be exploited in IncusOS. A fix is planned for
versions 6.0.6 and 6.21.0, but they have not been released at the time of publication. (CVE-2026-23954)

See Also

https://security.alpinelinux.org/vuln/CVE-2026-23953

https://security.alpinelinux.org/vuln/CVE-2026-23954

Plugin Details

Severity: High

ID: 436932

Version: Revision 1.3

Type: Local

Published: 1/25/2026

Updated: 7/2/2026

Supported Sensors: Agentless Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.8

Percentile: 57.62

CVSS v2

Risk Factor: High

Base Score: 7.1

Temporal Score: 5.6

Vector: CVSS2#AV:A/AC:L/Au:S/C:C/I:C/A:N

CVSS Score Source: CVE-2026-23954

CVSS v3

Risk Factor: High

Base Score: 8.7

Temporal Score: 7.8

Vector: CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Vulnerability Publication Date: 1/22/2026

Reference Information

CVE: CVE-2026-23953, CVE-2026-23954