Symlink-Following Vulnerability in Libvirt Affects Multiple Versions
CVE-2026-63622
Key Information:
- Vendor
Red Hat
- Status
- Vendor
- CVE Published:
- 10 August 2026
What is CVE-2026-63622?
A security vulnerability exists in libvirt that could permit a local attacker, particularly a process running as the confined swtpm user, to exploit a symlink-following flaw located in the virFileChownFiles() function. By creating a symbolic link within the swtpm state directory, the attacker can mislead the root-level libvirt daemon into changing the ownership of an arbitrary file to the swtpm user. This exploit facilitates privilege escalation, granting unauthorized control over file ownership at the root level.
Affected Version(s)
Red Hat Enterprise Linux 10.0 Extended Update Support 0:10.10.0-8.11.el10_0
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support 8060020260910092451.ad008a3a
Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On 8060020260910092451.ad008a3a
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved