Search CVE reports


Toggle filters

1 – 10 of 95 results


CVE-2025-13193

Medium priority
Needs evaluation

A flaw was found in libvirt. External inactive snapshots for shut-down VMs are incorrectly created as world-readable, making it possible for unprivileged users to inspect the guest OS contents. This results in an information...

1 affected package

libvirt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libvirt Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-12748

Medium priority
Needs evaluation

A flaw was discovered in libvirt in the XML file processing. More specifically, the parsing of user provided XML files was performed before the ACL checks. A malicious user with limited permissions could exploit this flaw by...

1 affected package

libvirt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libvirt Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-8235

Medium priority
Fixed

A flaw was found in libvirt. A refactor of the code fetching the list of interfaces for multiple APIs introduced a corner case on platforms where allocating 0 bytes of memory results in a NULL pointer. This corner case would lead...

1 affected package

libvirt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libvirt Not affected Not affected Not affected Not affected
Show less packages

CVE-2024-4418

Medium priority
Fixed

A race condition leading to a stack use-after-free flaw was found in libvirt. Due to a bad assumption in the virNetClientIOEventLoop() method, the `data` pointer to a stack-allocated virNetClientIOEventData structure ended up...

1 affected package

libvirt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libvirt Fixed Not affected Not affected Not affected
Show less packages

CVE-2024-2494

Medium priority

Some fixes available 7 of 10

A flaw was found in the RPC library APIs of libvirt. The RPC server deserialization code allocates memory for arrays before the non-negative length check is performed by the C API entry points. Passing a negative length to the...

1 affected package

libvirt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libvirt Fixed Fixed Fixed Needs evaluation
Show less packages

CVE-2024-2496

Medium priority

Some fixes available 3 of 6

A NULL pointer dereference flaw was found in the udevConnectListAllInterfaces() function in libvirt. This issue can occur when detaching a host interface while at the same time collecting the list of interfaces via...

1 affected package

libvirt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libvirt Not affected Fixed Fixed Needs evaluation
Show less packages

CVE-2024-1441

Medium priority

Some fixes available 7 of 10

An off-by-one error flaw was found in the udevListInterfacesByStatus() function in libvirt when the number of interfaces exceeds the size of the `names` array. This issue can be reproduced by sending specially crafted data to the...

1 affected package

libvirt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libvirt Fixed Fixed Fixed Needs evaluation
Show less packages

CVE-2023-3750

Medium priority

Some fixes available 1 of 2

A flaw was found in libvirt. The virStoragePoolObjListSearch function does not return a locked pool as expected, resulting in a race condition and denial of service when attempting to lock the same object from another thread. This...

1 affected package

libvirt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libvirt Not affected Not affected Not affected
Show less packages

CVE-2023-2700

Medium priority
Fixed

A vulnerability was found in libvirt. This security flaw ouccers due to repeatedly querying an SR-IOV PCI device's capabilities that exposes a memory leak caused by a failure to free the virPCIVirtualFunction array within the...

1 affected package

libvirt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libvirt Fixed Not affected Not affected
Show less packages

CVE-2022-0897

Low priority

Some fixes available 4 of 6

A flaw was found in the libvirt nwfilter driver. The virNWFilterObjListNumOfNWFilters method failed to acquire the driver->nwfilters mutex before iterating over virNWFilterObj instances. There was no protection to stop another...

1 affected package

libvirt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libvirt Not affected Fixed Fixed Fixed
Show less packages