Information Disclosure Vulnerability in Libvirt Product by Red Hat
CVE-2026-63623
5.5MEDIUM
What is CVE-2026-63623?
A flaw exists in the Libvirt utility that permits world-readable access to newly created volume images. This occurs during storage volume cloning or conversion processes, where improper file creation settings in the qemu-img utility allow local users to read sensitive data from guest virtual machines. This exposure can lead to unauthorized access to confidential information, making it crucial to address this issue promptly.
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank HE WEI (gikaku) for reporting this issue.