Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m7jx-933m-5cqr

Опубликовано: 10 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 5.5

Описание

A flaw was found in libvirt. During storage volume clone or convert operations, newly created volume images were temporarily world-readable. This was caused by the qemu-img utility running with overly permissive file creation settings, allowing any local user to read the full guest disk contents. This vulnerability could lead to sensitive information disclosure from guest virtual machines.

A flaw was found in libvirt. During storage volume clone or convert operations, newly created volume images were temporarily world-readable. This was caused by the qemu-img utility running with overly permissive file creation settings, allowing any local user to read the full guest disk contents. This vulnerability could lead to sensitive information disclosure from guest virtual machines.

EPSS

Процентиль: 1%
0.00095
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-732

Связанные уязвимости

CVSS3: 5.5
redhat
14 дней назад

A flaw was found in libvirt. During storage volume clone or convert operations, newly created volume images were temporarily world-readable. This was caused by the `qemu-img` utility running with overly permissive file creation settings, allowing any local user to read the full guest disk contents. This vulnerability could lead to sensitive information disclosure from guest virtual machines.

CVSS3: 5.5
nvd
2 дня назад

A flaw was found in libvirt. During storage volume clone or convert operations, newly created volume images were temporarily world-readable. This was caused by the `qemu-img` utility running with overly permissive file creation settings, allowing any local user to read the full guest disk contents. This vulnerability could lead to sensitive information disclosure from guest virtual machines.

CVSS3: 5.5
debian
2 дня назад

A flaw was found in libvirt. During storage volume clone or convert op ...

EPSS

Процентиль: 1%
0.00095
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-732