The Incus team is pleased to announce the release of Incus 7.3!
Another busy release for us, both on the feature front with quite a lot of exciting new features as well as on the performance, bugfix and securty front.

This fixes the following security issues:
- CVE-2026-62867 (critical) – Argument injection through storage volume
block.create_options - CVE-2026-62940 (critical) – Project restriction bypass via instance migration config override
- CVE-2026-62941 (critical) – Project restriction bypass via cross-project instance copy
- CVE-2026-63125 (critical) – Arbitrary file write on host via
backup.yamlsymlink in crafted image - CVE-2026-63343 (critical) – Arbitrary file read+write on host via
metadata.yamlsymlink in crafted image - GHSA-26gp-p5fw-3r2h (critical) – Arbitrary file write on host via path traversal in instance backup import
- GHSA-67qw-68v3-36h6 (critical) – Arbitrary file write on host via path traversal in custom volume import
- GHSA-7fj9-65v4-rp7h (critical) – Arbitrary file write on host via image-planted symlinks and
oci.dns.*newline injection - GHSA-p2v3-6wvc-cv3p (critical) – Arbitrary file write on host via image fingerprint path traversal
- GHSA-4qxq-p5hm-3q3p (high) – Arbitrary file read+write on host via VM template path traversal
- GHSA-m3j6-p3v3-qmjv (high) – Container configuration newline injection through
nvidia.driver.capabilities - CVE-2026-62313 (medium) – Project isolation restriction bypass by omitting
security.idmap.isolated - GHSA-6v6x-387m-rj4w (medium) – Project restriction bypass on network address sets
Note that some of the above don’t yet have CVE assigned. This is due to Github having a 3-4 weeks backlog on CVE assignments right now. We have requested CVEs for all the issues above and they will be automatically added to the relevant GHSA once allocated.
On the feature front, the highlights for this release are:
- GPU sharing for virtual machines through DRM native context
- UEFI variable management for virtual machines
- Instance port forwarding
- Reworked authorization configuration
- Introducing incus low-level
- BGP unnumbered support
- Control of nested virtualization
- Listing instances across all remotes
- Improved VM agent handling
- Network allocations improvements
- I/O limits improvements
- Storage pool metrics
- ACME External Account Binding
- CPU cluster reporting in the resources API
- Native Windows and macOS installers
The full announcement and changelog can be found here.
And for those who prefer videos, here’s the release overview video:
You can take the latest release of Incus up for a spin through our online demo service at: https://linuxcontainers.org/incus/try-it/
And as always, my company is offering commercial support on Incus, ranging from by-the-hour support contracts to one-off services on things like initial migration from LXD, review of your deployment to squeeze the most out of Incus or even feature sponsorship. You’ll find all details of that here: https://zabbly.com/incus
Donations towards my work on this and other open source projects is also always appreciated, you can find me on Github Sponsors, Patreon and Ko-fi.
Enjoy!




Github
Twitter
LinkedIn
Mastodon