{"schema_version":"1.9.0","id":"GHSA-x6jc-phwx-hp32","published":"2026-01-22T20:21:17Z","modified":"2026-03-27T22:34:09.180340Z","aliases":["CVE-2026-23953","GO-2026-4359"],"summary":"Incus container environment configuration newline injection","details":"### Summary\nA user with the ability to launch a container with a custom YAML configuration (e.g a member of the ‘incus’ group) can create an environment variable containing newlines, which can be used to add additional configuration items in the container’s `lxc.conf` due to the newline injection. This can allow adding arbitrary lifecycle hooks, ultimately resulting in arbitrary command execution on the host.\n\n### Details\nWhen passing environment variables in the config block of a new container, values are not checked for the presence of newlines [1], which can result in newline injection inside the generated container `lxc.conf`. This can be used to set arbitrary additional configuration items, such as `lxc.hook.pre-start`. By exploiting this, a user with the ability to launch a container with an arbitrary config can achieve arbitrary command execution as root on the host.\n\nExploiting this issue on IncusOS requires a slight modification of the payload to change to a different writable directory for the validation step (e.g /tmp). This can be confirmed with a second container with /tmp mounted from the host (A privileged action for validation only).\n\n[1] https://github.com/lxc/incus/blob/HEAD/internal/server/instance/drivers/driver_lxc.go#L1081\n\n### PoC\nA proof-of-concept script exploiting this vulnerability can be found attached, named environment_newline_injection.sh, showing arbitrary command execution, which will write a file to the root filesystem (`/newline_injection_command_exec_poc`)\n\nManual Reproduction steps:\n1. Launch a new container with a configuration file containing a multiline YAML string as an environment variable value, such as in the listing below.\n2. Observe that the lxc.conf (`/run/incus/user-1000_poc/lxc.conf` in my case) contains an additional `lxc.hook.pre-start` item\n3. Observe the creation of the file in the host root directory, with contents proving command execution as root.\n\n```\nincus launch images:alpine/edge --ephemeral poc << EOF\nconfig:\n  environment.FOO: |-\n    abc\n    lxc.hook.pre-start = /bin/sh -c \"id > /newline_injection_command_exec_poc\"\nEOF\n```\n\n### Impact\nA user with the ability to launch a container with a custom YAML configuration (e.g a member of the ‘incus’ group) can achieve arbitrary command execution on the host.\n\n### Attachments\n[environment_newline_injection.sh](https://github.com/user-attachments/files/24473682/environment_newline_injection.sh)\n[environment_newline_injection.patch](https://github.com/user-attachments/files/24473685/environment_newline_injection.patch)","affected":[{"package":{"name":"github.com/lxc/incus/v6","ecosystem":"Go","purl":"pkg:golang/github.com/lxc/incus/v6"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"6.21.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-x6jc-phwx-hp32/GHSA-x6jc-phwx-hp32.json"}}],"references":[{"type":"WEB","url":"https://github.com/lxc/incus/security/advisories/GHSA-x6jc-phwx-hp32"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-23953"},{"type":"PACKAGE","url":"https://github.com/lxc/incus"},{"type":"WEB","url":"https://github.com/lxc/incus/blob/HEAD/internal/server/instance/drivers/driver_lxc.go#L1081"},{"type":"WEB","url":"https://github.com/user-attachments/files/24473682/environment_newline_injection.sh"},{"type":"WEB","url":"https://github.com/user-attachments/files/24473685/environment_newline_injection.patch"}],"database_specific":{"cwe_ids":["CWE-93"],"github_reviewed":true,"github_reviewed_at":"2026-01-22T20:21:17Z","nvd_published_at":"2026-01-22T22:16:20Z","severity":"HIGH"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"}]}