PT-2026-80168 · Alpaquita+2 · Libvirt
CVE-2026-61478
·
Published
2026-08-08
·
Updated
2026-08-19
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
It was discovered that libvirt incorrectly handled guest reboots in the
libxl driver. An attacker in a guest could possibly use this issue to
cause the libvirt daemon to crash, resulting in a denial of service. This
issue only affected Ubuntu 16.04 LTS. (CVE-2021-4147)
Alexander Kuznetsov discovered that libvirt incorrectly handled listing
network interfaces. An attacker could possibly use this issue to cause
the libvirt daemon to crash, resulting in a denial of service. This issue
only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 18.04 LTS.
(CVE-2024-1441)
It was discovered that libvirt incorrectly handled certain values in its
RPC library. An attacker could possibly use this issue to cause the
libvirt daemon to crash, resulting in a denial of service. This issue
only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 18.04 LTS.
(CVE-2024-2494)
It was discovered that libvirt incorrectly handled listing network
interfaces under certain circumstances. An attacker could possibly use
this issue to cause the libvirt daemon to crash, resulting in a denial of
service. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and
Ubuntu 18.04 LTS. (CVE-2024-2496)
It was discovered that libvirt incorrectly set permissions on external
inactive snapshots, making them world-readable. A local attacker could
possibly use this issue to obtain sensitive information. This issue only
affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu
20.04 LTS. (CVE-2025-13193)
It was discovered that libvirt incorrectly handled certain characters in
virtual network definitions. An authenticated user could possibly use
this issue to inject arbitrary configuration directives and execute
arbitrary code as root. This issue did not affect Ubuntu 14.04 LTS.
(CVE-2026-61477)
It was discovered that libvirt incorrectly handled certain XML input. An
attacker could possibly use this issue to cause the libvirt daemon to
crash, resulting in a denial of service. (CVE-2026-61478)
He Wei discovered that libvirt incorrectly followed symbolic links when
changing file ownership. A local attacker could possibly use this issue
to escalate privileges. This issue only affected Ubuntu 20.04 LTS, Ubuntu
22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-63622)
It was discovered that libvirt incorrectly set permissions on images
during storage volume clone and convert operations, making them
temporarily world-readable. A local attacker could possibly use this
issue to obtain sensitive information. (CVE-2026-63623)
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Libvirt