Insufficient data authenticity validation In incus
Description
Incus does not verify combined fingerprint when downloading images from simplestreams servers in github.com/lxc/incus Incus does not verify combined fingerprint when downloading images from simplestreams servers in github.com/lxc/incus
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 13 | 6.0.4-2+deb13u5 | ||
debian 13 | 5.0.2+git20231211.1364ae4-9+deb13u4 | ||
debian 12 | 5.0.2-5+deb12u4 | ||
debian 14 | 6.0.6-2 | ||
go | 6.23.0 | ||
go | - | - | |
go | 6.23.0 |
Aliases
1. 2. 3. 4. 5. 6. 7. 8. 9.
References
1. 2. 3. 4. 5. 6.