Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r329-fjhj-3cw3

Опубликовано: 10 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

A flaw was found in libvirt. A local attacker, specifically a process running as the confined swtpm user, could exploit a symlink-following vulnerability in the virFileChownFiles() function. By planting a symbolic link within the swtpm state directory, the attacker could trick the root-level libvirt daemon into changing the ownership of an arbitrary file to the swtpm user. This allows for privilege escalation from the swtpm sandbox to root-level file ownership control.

A flaw was found in libvirt. A local attacker, specifically a process running as the confined swtpm user, could exploit a symlink-following vulnerability in the virFileChownFiles() function. By planting a symbolic link within the swtpm state directory, the attacker could trick the root-level libvirt daemon into changing the ownership of an arbitrary file to the swtpm user. This allows for privilege escalation from the swtpm sandbox to root-level file ownership control.

EPSS

Процентиль: 3%
0.0013
Низкий

7.8 High

CVSS3

Дефекты

CWE-59

Связанные уязвимости

CVSS3: 7.8
redhat
14 дней назад

A flaw was found in libvirt. A local attacker, specifically a process running as the confined `swtpm` user, could exploit a symlink-following vulnerability in the `virFileChownFiles()` function. By planting a symbolic link within the `swtpm` state directory, the attacker could trick the root-level libvirt daemon into changing the ownership of an arbitrary file to the `swtpm` user. This allows for privilege escalation from the `swtpm` sandbox to root-level file ownership control.

CVSS3: 7.8
nvd
2 дня назад

A flaw was found in libvirt. A local attacker, specifically a process running as the confined `swtpm` user, could exploit a symlink-following vulnerability in the `virFileChownFiles()` function. By planting a symbolic link within the `swtpm` state directory, the attacker could trick the root-level libvirt daemon into changing the ownership of an arbitrary file to the `swtpm` user. This allows for privilege escalation from the `swtpm` sandbox to root-level file ownership control.

CVSS3: 7.8
debian
2 дня назад

A flaw was found in libvirt. A local attacker, specifically a process ...

EPSS

Процентиль: 3%
0.0013
Низкий

7.8 High

CVSS3

Дефекты

CWE-59