{"id":"GHSA-fwj8-62r8-8p8m","summary":"Incus has Nil-Pointer Dereference via S3 Bucket Import","details":"### Summary\nMissing error handling could lead an authenticated Incus user to cause a daemon crash through the import of a truncated storage bucket backup file.\n\n### Details\nIt was found that TransferManager.UploadAllFiles iterates over tar entries but only checks for io.EOF from tr.Next(). When tr.Next() returns a non-EOF error, such as unexpected EOF from a truncated archive, the header hdr is nil and the code continues to access hdr.Name, causing a nil-pointer dereference that panics the daemon.\n\nThis may allow the Incus daemon to be crashed during S3 bucket restore if a truncated or corrupted backup archive is provided. A panic can occur when a malformed archive produces a non-EOF tar read error after the first entry. Any caller of UploadAllFiles that processes attacker-controlled archive content may be affected.\n\nAffected File:\n[https://github.com/lxc/incus/blob/v6.22.0/…server/storage/s3/transfer_manager.go#L127](https://github.com/lxc/incus/blob/v6.22.0/internal/server/storage/s3/transfer_manager.go#L127) \n\nThe tar-iteration loop only checks for EOF:\n\nAffected Code:\n```\nfor {\n    hdr, err := tr.Next()\n    if err == io.EOF {\n        break // End of archive.\n    }\n\n    // Skip index.yaml file\n    if hdr.Name == \"backup/index.yaml\" {\n```\n\nWhen tr.Next() returns a non-EOF error, hdr is nil. The code does not check for this case and immediately dereferences hdr.Name.\n\nThis was confirmed as follows:\n\nCommand:\n```\ngo test ./test/fuzz -run='FuzzS3BucketUploadTarParsing/s3_nil_deref_truncated_tar' -count=1 -v\n```\n\nOutput:\n```\n=== RUN   FuzzS3BucketUploadTarParsing\n=== RUN   FuzzS3BucketUploadTarParsing/s3_nil_deref_truncated_tar\n   s3_bucket_upload_fuzz_test.go:82: UploadAllFiles panicked: runtime error: invalid memory address\n       or nil pointer dereference\n--- FAIL: FuzzS3BucketUploadTarParsing/s3_nil_deref_truncated_tar (0.00s)\nFAIL\n```\n\nIt is recommended to add a non-EOF error check after tr.Next().\n\nProposed Fix:\n```\nhdr, err := tr.Next()\nif err == io.EOF {\n    break\n}\n\nif err != nil {\n    return fmt.Errorf(\"Error reading backup archive: %w\", err)\n}\n```\n\nA patch is available at https://github.com/lxc/incus/releases/tag/v7.0.0.\n\n### Credits\nThis issue was discovered and reported by the team at 7asecurity (https://7asecurity.com/)","aliases":["CVE-2026-41647","GO-2026-5384"],"modified":"2026-06-25T23:11:43.584949556Z","published":"2026-05-04T19:38:48Z","database_specific":{"nvd_published_at":"2026-05-07T14:16:03Z","cwe_ids":["CWE-476"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-05-04T19:38:48Z"},"references":[{"type":"WEB","url":"https://github.com/lxc/incus/security/advisories/GHSA-fwj8-62r8-8p8m"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41647"},{"type":"PACKAGE","url":"https://github.com/lxc/incus"},{"type":"WEB","url":"https://github.com/lxc/incus/releases/tag/v7.0.0"}],"affected":[{"package":{"name":"github.com/lxc/incus/v6/cmd/incusd","ecosystem":"Go","purl":"pkg:golang/github.com/lxc/incus/v6/cmd/incusd"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"6.23.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-fwj8-62r8-8p8m/GHSA-fwj8-62r8-8p8m.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}