Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-13193

Опубликовано: 17 нояб. 2025
Источник: debian
EPSS Низкий

Описание

A flaw was found in libvirt. External inactive snapshots for shut-down VMs are incorrectly created as world-readable, making it possible for unprivileged users to inspect the guest OS contents. This results in an information disclosure vulnerability.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libvirtfixed11.10.0-1package
libvirtfixed11.3.0-3+deb13u2trixiepackage
libvirtnot-affectedbookwormpackage
libvirtnot-affectedbullseyepackage

Примечания

  • Introduced after: https://gitlab.com/libvirt/libvirt/-/commit/9b94a9e8ab1de1a33fa97e0362b1e763b09d52c8 (v9.7.0-rc1)

  • Fixed by: https://gitlab.com/libvirt/libvirt/-/commit/a379327d8abcde8ac8d3e16fe5e4ba6f790d767a

EPSS

Процентиль: 13%
0.00043
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
3 месяца назад

A flaw was found in libvirt. External inactive snapshots for shut-down VMs are incorrectly created as world-readable, making it possible for unprivileged users to inspect the guest OS contents. This results in an information disclosure vulnerability.

CVSS3: 5.5
nvd
3 месяца назад

A flaw was found in libvirt. External inactive snapshots for shut-down VMs are incorrectly created as world-readable, making it possible for unprivileged users to inspect the guest OS contents. This results in an information disclosure vulnerability.

CVSS3: 5.5
msrc
3 месяца назад

Libvirt: information disclosure via world-readable vm snapshots

CVSS3: 5.5
github
3 месяца назад

A flaw was found in libvirt. External inactive snapshots for shut-down VMs are incorrectly created as world-readable, making it possible for unprivileged users to inspect the guest OS contents. This results in an information disclosure vulnerability.

suse-cvrf
2 месяца назад

Security update for libvirt

EPSS

Процентиль: 13%
0.00043
Низкий