Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-63622

Опубликовано: 30 июл. 2026
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

A flaw was found in libvirt. A local attacker, specifically a process running as the confined swtpm user, could exploit a symlink-following vulnerability in the virFileChownFiles() function. By planting a symbolic link within the swtpm state directory, the attacker could trick the root-level libvirt daemon into changing the ownership of an arbitrary file to the swtpm user. This allows for privilege escalation from the swtpm sandbox to root-level file ownership control.

Меры по смягчению последствий

If virtual Trusted Platform Module (vTPM) functionality is not required, remove the device definition from the domain XML configuration to prevent the vulnerable code path from being reached. To check if a domain uses vTPM:

virsh dumpxml <domain> | grep -A5 '<tpm'

To remove it, edit the domain XML and delete the block. This prevents libvirt from spawning swtpm processes and from calling virFileChownFiles() on the swtpm state directory during domain startup. Domains that require vTPM for guest OS functionality cannot use this mitigation and should prioritize applying the upstream fix.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10libvirtAffected
Red Hat Enterprise Linux 6libvirtNot affected
Red Hat Enterprise Linux 7libvirtAffected
Red Hat Enterprise Linux 8virt:rhel/libvirtAffected
Red Hat Enterprise Linux 9libvirtAffected
Red Hat Enterprise Linux for NVIDIA 26libvirtOut of support scope

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-59
https://bugzilla.redhat.com/show_bug.cgi?id=2513065libvirt: swtpm privilege escalation via symlink following

EPSS

Процентиль: 3%
0.0013
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
nvd
2 дня назад

A flaw was found in libvirt. A local attacker, specifically a process running as the confined `swtpm` user, could exploit a symlink-following vulnerability in the `virFileChownFiles()` function. By planting a symbolic link within the `swtpm` state directory, the attacker could trick the root-level libvirt daemon into changing the ownership of an arbitrary file to the `swtpm` user. This allows for privilege escalation from the `swtpm` sandbox to root-level file ownership control.

CVSS3: 7.8
debian
2 дня назад

A flaw was found in libvirt. A local attacker, specifically a process ...

CVSS3: 7.8
github
2 дня назад

A flaw was found in libvirt. A local attacker, specifically a process running as the confined `swtpm` user, could exploit a symlink-following vulnerability in the `virFileChownFiles()` function. By planting a symbolic link within the `swtpm` state directory, the attacker could trick the root-level libvirt daemon into changing the ownership of an arbitrary file to the `swtpm` user. This allows for privilege escalation from the `swtpm` sandbox to root-level file ownership control.

EPSS

Процентиль: 3%
0.0013
Низкий

7.8 High

CVSS3