Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-63623

Опубликовано: 10 авг. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 5.5

Описание

A flaw was found in libvirt. During storage volume clone or convert operations, newly created volume images were temporarily world-readable. This was caused by the qemu-img utility running with overly permissive file creation settings, allowing any local user to read the full guest disk contents. This vulnerability could lead to sensitive information disclosure from guest virtual machines.

РелизСтатусПримечание
devel

not-affected

12.6.0-1ubuntu1
esm-infra-legacy/trusty

released

1.2.2-0ubuntu13.1.28+esm2
esm-infra-legacy/xenial

released

1.3.1-1ubuntu10.31+esm1
esm-infra/bionic

released

4.0.0-1ubuntu8.21+esm1
esm-infra/focal

released

6.0.0-0ubuntu8.20+esm1
jammy

released

8.0.0-1ubuntu7.19
noble

released

10.0.0-2ubuntu8.16
resolute

released

12.0.0-1ubuntu5.3
upstream

released

12.6.0-1

Показывать по

РелизСтатусПримечание
devel

needs-triage

jammy

DNE

noble

DNE

resolute

needs-triage

upstream

needs-triage

Показывать по

EPSS

Процентиль: 1%
0.00095
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
redhat
около 1 месяца назад

A flaw was found in libvirt. During storage volume clone or convert operations, newly created volume images were temporarily world-readable. This was caused by the `qemu-img` utility running with overly permissive file creation settings, allowing any local user to read the full guest disk contents. This vulnerability could lead to sensitive information disclosure from guest virtual machines.

CVSS3: 5.5
nvd
24 дня назад

A flaw was found in libvirt. During storage volume clone or convert operations, newly created volume images were temporarily world-readable. This was caused by the `qemu-img` utility running with overly permissive file creation settings, allowing any local user to read the full guest disk contents. This vulnerability could lead to sensitive information disclosure from guest virtual machines.

CVSS3: 5.5
msrc
20 дней назад

Libvirt: information disclosure via world-readable storage volume images during clone/convert

CVSS3: 5.5
debian
24 дня назад

A flaw was found in libvirt. During storage volume clone or convert op ...

CVSS3: 5.5
github
24 дня назад

A flaw was found in libvirt. During storage volume clone or convert operations, newly created volume images were temporarily world-readable. This was caused by the `qemu-img` utility running with overly permissive file creation settings, allowing any local user to read the full guest disk contents. This vulnerability could lead to sensitive information disclosure from guest virtual machines.

EPSS

Процентиль: 1%
0.00095
Низкий

5.5 Medium

CVSS3