Debian Package Tracker
Register | Log in
Subscribe

incus

Modern container and virtual machine manager - daemon

Choose email to subscribe with

general
  • source: incus (main)
  • version: 7.0.0-1
  • maintainer: Debian Go Packaging Team (DMD)
  • uploaders: Free Ekanayaka [DMD] – Mathias Gibbens [DMD]
  • arch: all any
  • std-ver: 4.7.4
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • old-bpo: 6.0.4-2+deb13u7~bpo12+1
  • stable: 6.0.4-2+deb13u4
  • stable-sec: 6.0.4-2+deb13u7
  • stable-p-u: 6.0.4-2+deb13u7
  • testing: 6.0.6-3
  • unstable: 7.0.0-1
versioned links
  • 6.0.4-2+deb13u4: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 6.0.4-2+deb13u7~bpo12+1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 6.0.4-2+deb13u7: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 6.0.6-3: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 7.0.0-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • golang-github-lxc-incus-dev
  • incus (2 bugs: 0, 2, 0, 0)
  • incus-agent
  • incus-base
  • incus-client
  • incus-extra
action needed
Debci reports failed tests high
  • unstable: tmpfail (log)
    The tests ran in 0:00:05
    Last run: 2026-04-18T11:53:37.000Z
    Previous status: unknown

  • testing: fail (log)
    The tests ran in 0:15:16
    Last run: 2026-04-12T19:32:39.000Z
    Previous status: unknown

  • stable: pass (log)
    The tests ran in 0:03:24
    Last run: 2025-11-09T17:34:44.000Z
    Previous status: unknown

Created: 2026-04-12 Last update: 2026-05-06 23:05
9 security issues in forky high

There are 9 open security issues in forky.

9 important issues:
  • CVE-2026-35527: Incus is an open source container and virtual machine manager. In versions prior to 7.0.0, the image import flow issues an outbound HEAD request to a user-supplied URL before validating the request against project restrictions such as restricted.images.servers. The imgPostURLInfo function constructs and sends a HEAD request directly from the attacker-supplied source URL to resolve image metadata, and this network interaction occurs before the flow reaches the point where the import would be rejected by policy. Although the actual image download is blocked by the project restriction, an authenticated user can coerce the daemon into making blind HEAD requests to arbitrary destinations. These requests include server metadata in custom headers (Incus-Server-Architectures, Incus-Server-Version), which discloses information about the host environment to the attacker-controlled endpoint. This blind SSRF primitive can be used to probe internal services, unroutable address space, or cloud metadata endpoints reachable from the host. This vulnerability pattern is similar to CVE-2026-24767. This issue has been fixed in version 7.0.0.
  • CVE-2026-40195:
  • CVE-2026-40197:
  • CVE-2026-40243:
  • CVE-2026-40251:
  • CVE-2026-41647:
  • CVE-2026-41648:
  • CVE-2026-41684:
  • CVE-2026-41685:
Created: 2026-05-01 Last update: 2026-05-06 13:30
debian/patches: 3 patches to forward upstream low

Among the 7 debian patches available in version 7.0.0-1 of the package, we noticed the following issues:

  • 3 patches where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2024-08-18 Last update: 2026-05-06 12:33
Issues found with some translations low

Automatic checks made by the Debian l10n team found some issues with the translations contained in this package. You should check the l10n status report for more information.

Issues can be things such as missing translations, problematic translated strings, outdated PO files, unknown languages, etc.

Created: 2024-01-18 Last update: 2025-04-05 23:55
testing migrations
  • excuses:
    • Migrates after: golang-github-aws-aws-sdk-go-v2, golang-github-aws-smithy-go
    • Migration status for incus (6.0.6-3 to 7.0.0-1): Waiting for test results or another package, or too young (no action required now - check later)
    • Issues preventing migration:
    • ∙ ∙ Autopkgtest for distrobuilder: amd64: Test triggered, arm64: Test triggered, i386: Test triggered, ppc64el: Test triggered, riscv64: Test triggered, s390x: Test triggered
    • ∙ ∙ Autopkgtest for incant: amd64: Test triggered, arm64: Test triggered, i386: Test triggered, ppc64el: Test triggered, riscv64: Test triggered, s390x: Test triggered
    • ∙ ∙ Autopkgtest for incus: amd64: Test triggered, arm64: Test triggered, i386: Test triggered, ppc64el: Test triggered, riscv64: Test triggered, s390x: Test triggered
    • ∙ ∙ Too young, only 1 of 5 days old
    • ∙ ∙ Build-Depends(-Arch): incus golang-github-aws-aws-sdk-go-v2
    • ∙ ∙ Built-Using: incus golang-github-aws-aws-sdk-go-v2
    • ∙ ∙ Built-Using: incus golang-github-aws-smithy-go
    • ∙ ∙ Depends: incus golang-github-aws-aws-sdk-go-v2
    • Additional info (not blocking):
    • ∙ ∙ Updating incus will fix bugs in testing: #1135644
    • ∙ ∙ Piuparts tested OK - https://piuparts.debian.org/sid/source/i/incus.html
    • ∙ ∙ Reproduced on amd64
    • ∙ ∙ Reproduced on arm64
    • ∙ ∙ Reproduced on armhf
    • ∙ ∙ Reproducibility check waiting for results on i386
    • ∙ ∙ Reproducibility check waiting for results on ppc64el
    • Not considered
news
[rss feed]
  • [2026-05-06] Accepted incus 7.0.0-1 (source) into unstable (Mathias Gibbens)
  • [2026-05-03] Accepted incus 6.0.4-2+deb13u7 (source) into proposed-updates (Debian FTP Masters) (signed by: Mathias Gibbens)
  • [2026-05-03] Accepted incus 6.0.4-2+deb13u7~bpo12+1 (source) into oldstable-backports (Mathias Gibbens)
  • [2026-05-02] Accepted incus 6.0.4-2+deb13u7 (source) into stable-security (Debian FTP Masters) (signed by: Mathias Gibbens)
  • [2026-04-18] Accepted incus 6.0.4-2+deb13u6 (source) into proposed-updates (Debian FTP Masters) (signed by: Mathias Gibbens)
  • [2026-04-17] incus 6.0.6-3 MIGRATED to testing (Debian testing watch)
  • [2026-04-16] Accepted incus 6.0.4-2+deb13u6~bpo12+1 (source) into oldstable-backports (Mathias Gibbens)
  • [2026-04-15] Accepted incus 6.0.4-2+deb13u6 (source) into stable-security (Debian FTP Masters) (signed by: Mathias Gibbens)
  • [2026-04-14] Accepted incus 6.0.6-3 (source) into unstable (Mathias Gibbens)
  • [2026-04-02] Accepted incus 6.0.4-2+deb13u5 (source) into proposed-updates (Debian FTP Masters) (signed by: Mathias Gibbens)
  • [2026-03-31] incus 6.0.6-2 MIGRATED to testing (Debian testing watch)
  • [2026-03-29] Accepted incus 6.0.4-2+deb13u5~bpo12+1 (source) into oldstable-backports (Mathias Gibbens)
  • [2026-03-29] Accepted incus 6.0.4-2+deb13u5 (source) into stable-security (Debian FTP Masters) (signed by: Mathias Gibbens)
  • [2026-03-27] Accepted incus 6.23.0-1~exp1 (source) into experimental (Mathias Gibbens)
  • [2026-03-26] Accepted incus 6.0.6-2 (source) into unstable (Mathias Gibbens)
  • [2026-03-25] incus 6.0.6-1 MIGRATED to testing (Debian testing watch)
  • [2026-03-15] Accepted incus 6.0.6-1 (source) into unstable (Mathias Gibbens)
  • [2026-02-28] Accepted incus 6.22.0-1~exp1 (source) into experimental (Mathias Gibbens)
  • [2026-01-26] Accepted incus 6.0.4-2+deb13u4~bpo12+1 (source) into oldstable-backports (Mathias Gibbens)
  • [2026-01-25] incus 6.0.5-8 MIGRATED to testing (Debian testing watch)
  • [2026-01-24] Accepted incus 6.0.4-2+deb13u4 (source) into proposed-updates (Debian FTP Masters) (signed by: Mathias Gibbens)
  • [2026-01-23] Accepted incus 6.0.4-2+deb13u4 (source) into stable-security (Debian FTP Masters) (signed by: Mathias Gibbens)
  • [2026-01-23] Accepted incus 6.21.0-1~exp1 (source) into experimental (Mathias Gibbens)
  • [2026-01-23] Accepted incus 6.0.5-8 (source) into unstable (Mathias Gibbens)
  • [2026-01-10] Accepted incus 6.0.4-2+deb13u3~bpo12+1 (source) into oldstable-backports (Mathias Gibbens)
  • [2025-12-20] Accepted incus 6.20.0-1~exp1 (source) into experimental (Mathias Gibbens)
  • [2025-12-20] Accepted incus 6.0.4-2+deb13u3 (source) into proposed-updates (Debian FTP Masters) (signed by: Mathias Gibbens)
  • [2025-12-16] incus 6.0.5-7 MIGRATED to testing (Debian testing watch)
  • [2025-12-11] Accepted incus 6.0.5-7 (source) into unstable (Simon Josefsson)
  • [2025-11-25] incus 6.0.5-6 MIGRATED to testing (Debian testing watch)
  • 1
  • 2
bugs [bug history graph]
  • all: 3
  • RC: 0
  • I&N: 2
  • M&W: 1
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian
  • buildd: logs, reproducibility, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
  • l10n (-, 14)
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 6.0.5-8
  • 2 bugs

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing