Symlink-Following Vulnerability in Libvirt Affects Multiple Versions
CVE-2026-63622

7.8HIGH

What is CVE-2026-63622?

A security vulnerability exists in libvirt that could permit a local attacker, particularly a process running as the confined swtpm user, to exploit a symlink-following flaw located in the virFileChownFiles() function. By creating a symbolic link within the swtpm state directory, the attacker can mislead the root-level libvirt daemon into changing the ownership of an arbitrary file to the swtpm user. This exploit facilitates privilege escalation, granting unauthorized control over file ownership at the root level.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank HE WEI (gikaku) for reporting this issue.
.