Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:18326

Опубликовано: 29 мая 2026
Источник: rocky
Оценка: Moderate

Описание

Moderate: libvirt security update

Kernel-based Virtual Machine (KVM) offers a full virtualization solution forLinux on numerous hardware platforms. The virt:rhel module contains packageswhich provide user-space components used to run virtual machines using KVM.The packages also provide APIs for managing and interacting with the virtualized systems.

Security Fix(es):

  • libvirt: Denial of service in XML parsing (CVE-2025-12748)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Rocky Linux 10 Release Notes linked from the References section.

Затронутые продукты

  • Rocky Linux 10

НаименованиеАрхитектураРелизRPM
libvirt-daemon-driver-networkx86_6412.1.el10_2libvirt-daemon-driver-network-11.10.0-12.1.el10_2.x86_64.rpm
libvirt-daemon-driver-storage-mpathx86_6412.1.el10_2libvirt-daemon-driver-storage-mpath-11.10.0-12.1.el10_2.x86_64.rpm
libvirt-daemon-driver-storage-corex86_6412.1.el10_2libvirt-daemon-driver-storage-core-11.10.0-12.1.el10_2.x86_64.rpm
libvirt-ssh-proxyx86_6412.1.el10_2libvirt-ssh-proxy-11.10.0-12.1.el10_2.x86_64.rpm
libvirt-daemonx86_6412.1.el10_2libvirt-daemon-11.10.0-12.1.el10_2.x86_64.rpm
libvirt-daemon-driver-interfacex86_6412.1.el10_2libvirt-daemon-driver-interface-11.10.0-12.1.el10_2.x86_64.rpm
libvirt-daemon-driver-secretx86_6412.1.el10_2libvirt-daemon-driver-secret-11.10.0-12.1.el10_2.x86_64.rpm
libvirt-daemon-config-networkx86_6412.1.el10_2libvirt-daemon-config-network-11.10.0-12.1.el10_2.x86_64.rpm
libvirt-daemon-proxyx86_6412.1.el10_2libvirt-daemon-proxy-11.10.0-12.1.el10_2.x86_64.rpm
libvirt-daemon-driver-storage-iscsix86_6412.1.el10_2libvirt-daemon-driver-storage-iscsi-11.10.0-12.1.el10_2.x86_64.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 5.5
ubuntu
9 месяцев назад

A flaw was discovered in libvirt in the XML file processing. More specifically, the parsing of user provided XML files was performed before the ACL checks. A malicious user with limited permissions could exploit this flaw by submitting a specially crafted XML file, causing libvirt to allocate too much memory on the host. The excessive memory consumption could lead to a libvirt process crash on the host, resulting in a denial-of-service condition.

CVSS3: 5.5
redhat
9 месяцев назад

A flaw was discovered in libvirt in the XML file processing. More specifically, the parsing of user provided XML files was performed before the ACL checks. A malicious user with limited permissions could exploit this flaw by submitting a specially crafted XML file, causing libvirt to allocate too much memory on the host. The excessive memory consumption could lead to a libvirt process crash on the host, resulting in a denial-of-service condition.

CVSS3: 5.5
nvd
9 месяцев назад

A flaw was discovered in libvirt in the XML file processing. More specifically, the parsing of user provided XML files was performed before the ACL checks. A malicious user with limited permissions could exploit this flaw by submitting a specially crafted XML file, causing libvirt to allocate too much memory on the host. The excessive memory consumption could lead to a libvirt process crash on the host, resulting in a denial-of-service condition.

CVSS3: 5.5
msrc
8 месяцев назад

Libvirt: denial of service in xml parsing

CVSS3: 5.5
debian
9 месяцев назад

A flaw was discovered in libvirt in the XML file processing. More spec ...