Symlink-Following Vulnerability in Libvirt QEMU TPM Emulator Function
CVE-2026-77159

5.5MEDIUM

What is CVE-2026-77159?

A vulnerability has been discovered in the libvirt's qemuTPMEmulatorPrepareHost() function, which permits a local attacker who has access to the swtpm account to exploit a symlink-following flaw. This flaw arises when the function conducts a path-based chown() on the swtpm logfile without verifying for symbolic links. By replacing the logfile with a symlink, the libvirtd service, which operates with root privileges, may inadvertently transfer ownership of arbitrary files to the swtpm user, potentially compromising system integrity and data security.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Suraj Theekshana for reporting this issue.
.