Search CVE reports


Toggle filters

1 – 10 of 100 results


CVE-2026-18917

Medium priority
Needs evaluation

(A flaw was found in libvirt. An unprivileged local user could exploit ...)

1 affected package

libvirt

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libvirt Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-61478

Medium priority
Fixed

[Unknown description]

1 affected package

libvirt

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libvirt Fixed Fixed Fixed Fixed Fixed
Show less packages

CVE-2026-63622

Medium priority
Fixed

A flaw was found in libvirt. A local attacker, specifically a process running as the confined `swtpm` user, could exploit a symlink-following vulnerability in the `virFileChownFiles()` function. By planting a symbolic link within...

1 affected package

libvirt

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libvirt Fixed Fixed Fixed Fixed Not affected
Show less packages

CVE-2026-63623

Medium priority
Fixed

A flaw was found in libvirt. During storage volume clone or convert operations, newly created volume images were temporarily world-readable. This was caused by the `qemu-img` utility running with overly permissive file creation...

1 affected package

libvirt

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libvirt Fixed Fixed Fixed Fixed Fixed
Show less packages

CVE-2026-61477

Medium priority

Some fixes available 6 of 7

An injection vulnerability was found in libvirt's virtual network driver. The network XML parser does not strip newline characters from DNS TXT record value attributes and SRV record domain/target attributes. These values are...

1 affected package

libvirt

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libvirt Fixed Fixed Fixed Fixed Fixed
Show less packages

CVE-2025-13193

Medium priority
Fixed

A flaw was found in libvirt. External inactive snapshots for shut-down VMs are incorrectly created as world-readable, making it possible for unprivileged users to inspect the guest OS contents. This results in an information...

1 affected package

libvirt

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libvirt Fixed Fixed Fixed Fixed Fixed
Show less packages

CVE-2025-12748

Medium priority

Some fixes available 5 of 9

A flaw was discovered in libvirt in the XML file processing. More specifically, the parsing of user provided XML files was performed before the ACL checks. A malicious user with limited permissions could exploit this flaw by...

1 affected package

libvirt

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libvirt Fixed Fixed Fixed Ignored Ignored
Show less packages

CVE-2024-8235

Medium priority
Fixed

A flaw was found in libvirt. A refactor of the code fetching the list of interfaces for multiple APIs introduced a corner case on platforms where allocating 0 bytes of memory results in a NULL pointer. This corner case would lead...

1 affected package

libvirt

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libvirt Not affected Not affected Not affected Not affected
Show less packages

CVE-2024-4418

Medium priority
Fixed

A race condition leading to a stack use-after-free flaw was found in libvirt. Due to a bad assumption in the virNetClientIOEventLoop() method, the `data` pointer to a stack-allocated virNetClientIOEventData structure ended up...

1 affected package

libvirt

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libvirt Fixed Not affected Not affected Not affected
Show less packages

CVE-2024-2494

Medium priority
Fixed

A flaw was found in the RPC library APIs of libvirt. The RPC server deserialization code allocates memory for arrays before the non-negative length check is performed by the C API entry points. Passing a negative length to the...

1 affected package

libvirt

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libvirt Fixed Fixed Fixed Fixed Fixed
Show less packages