Search CVE reports


Toggle filters

1 – 6 of 6 results


CVE-2026-77159

Medium priority

Some fixes available 4 of 8

A symlink-following flaw was found in libvirt's qemuTPMEmulatorPrepareHost() function. The function uses a path-based chown() on the swtpm logfile without checking for symbolic links. A local attacker with access to the swtpm...

2 affected packages

libvirt, libvirt-hwe

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libvirt Fixed Fixed Fixed Needs evaluation Needs evaluation
libvirt-hwe Fixed Not in release Not in release — —
Show less packages

CVE-2026-18917

Medium priority

Some fixes available 4 of 8

A flaw was found in libvirt. An unprivileged local user could exploit an integer overflow vulnerability in the NodeGetFreePages RPC handler. This flaw allows crafted values to bypass a size check, leading to an undersized memory...

2 affected packages

libvirt, libvirt-hwe

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libvirt Fixed Fixed Fixed Needs evaluation Needs evaluation
libvirt-hwe Fixed Not in release Not in release — —
Show less packages

CVE-2026-61478

Medium priority
Fixed

[Unknown description]

2 affected packages

libvirt, libvirt-hwe

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libvirt Fixed Fixed Fixed Fixed Fixed
libvirt-hwe Fixed Not in release Not in release — —
Show less packages

CVE-2026-63622

Medium priority
Fixed

A flaw was found in libvirt. A local attacker, specifically a process running as the confined `swtpm` user, could exploit a symlink-following vulnerability in the `virFileChownFiles()` function. By planting a symbolic link within...

2 affected packages

libvirt, libvirt-hwe

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libvirt Fixed Fixed Fixed Fixed Not affected
libvirt-hwe Fixed Not in release Not in release — —
Show less packages

CVE-2026-63623

Medium priority
Fixed

A flaw was found in libvirt. During storage volume clone or convert operations, newly created volume images were temporarily world-readable. This was caused by the `qemu-img` utility running with overly permissive file creation...

2 affected packages

libvirt, libvirt-hwe

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libvirt Fixed Fixed Fixed Fixed Fixed
libvirt-hwe Fixed Not in release Not in release — —
Show less packages

CVE-2026-61477

Medium priority

Some fixes available 7 of 8

An injection vulnerability was found in libvirt's virtual network driver. The network XML parser does not strip newline characters from DNS TXT record value attributes and SRV record domain/target attributes. These values are...

2 affected packages

libvirt, libvirt-hwe

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libvirt Fixed Fixed Fixed Fixed Fixed
libvirt-hwe Fixed Not in release Not in release — —
Show less packages