Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:18748

Опубликовано: 28 мая 2026
Источник: rocky
Оценка: Moderate

Описание

Moderate: libvirt security update

Kernel-based Virtual Machine (KVM) offers a full virtualization solution forLinux on numerous hardware platforms. The virt:rhel module contains packageswhich provide user-space components used to run virtual machines using KVM.The packages also provide APIs for managing and interacting with the virtualized systems.

Security Fix(es):

  • libvirt: Denial of service in XML parsing (CVE-2025-12748)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Rocky Linux 9 Release Notes linked from the References section.

Затронутые продукты

  • Rocky Linux 9

НаименованиеАрхитектураРелизRPM
libvirtaarch6412.el9libvirt-11.10.0-12.el9.aarch64.rpm
libvirt-clientaarch6412.el9libvirt-client-11.10.0-12.el9.aarch64.rpm
libvirt-client-qemuaarch6412.el9libvirt-client-qemu-11.10.0-12.el9.aarch64.rpm
libvirt-daemonaarch6412.el9libvirt-daemon-11.10.0-12.el9.aarch64.rpm
libvirt-daemon-commonaarch6412.el9libvirt-daemon-common-11.10.0-12.el9.aarch64.rpm
libvirt-daemon-config-networkaarch6412.el9libvirt-daemon-config-network-11.10.0-12.el9.aarch64.rpm
libvirt-daemon-config-nwfilteraarch6412.el9libvirt-daemon-config-nwfilter-11.10.0-12.el9.aarch64.rpm
libvirt-daemon-driver-interfaceaarch6412.el9libvirt-daemon-driver-interface-11.10.0-12.el9.aarch64.rpm
libvirt-daemon-driver-networkaarch6412.el9libvirt-daemon-driver-network-11.10.0-12.el9.aarch64.rpm
libvirt-daemon-driver-nodedevaarch6412.el9libvirt-daemon-driver-nodedev-11.10.0-12.el9.aarch64.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 5.5
ubuntu
9 месяцев назад

A flaw was discovered in libvirt in the XML file processing. More specifically, the parsing of user provided XML files was performed before the ACL checks. A malicious user with limited permissions could exploit this flaw by submitting a specially crafted XML file, causing libvirt to allocate too much memory on the host. The excessive memory consumption could lead to a libvirt process crash on the host, resulting in a denial-of-service condition.

CVSS3: 5.5
redhat
9 месяцев назад

A flaw was discovered in libvirt in the XML file processing. More specifically, the parsing of user provided XML files was performed before the ACL checks. A malicious user with limited permissions could exploit this flaw by submitting a specially crafted XML file, causing libvirt to allocate too much memory on the host. The excessive memory consumption could lead to a libvirt process crash on the host, resulting in a denial-of-service condition.

CVSS3: 5.5
nvd
9 месяцев назад

A flaw was discovered in libvirt in the XML file processing. More specifically, the parsing of user provided XML files was performed before the ACL checks. A malicious user with limited permissions could exploit this flaw by submitting a specially crafted XML file, causing libvirt to allocate too much memory on the host. The excessive memory consumption could lead to a libvirt process crash on the host, resulting in a denial-of-service condition.

CVSS3: 5.5
msrc
8 месяцев назад

Libvirt: denial of service in xml parsing

CVSS3: 5.5
debian
9 месяцев назад

A flaw was discovered in libvirt in the XML file processing. More spec ...