Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3021▲ 414 respecto a la semana anterior
Críticas / altas1420▲ 180 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)383▲ 169 respecto a la semana anterior
97 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.5) | 0.16% | — | LibvirtAI | 11/9/2026 | 16/9/2026 | A symlink-following flaw was found in libvirt's qemuTPMEmulatorPrepareHost() function. The function uses a path-based chown() on the swtpm logfile without checking for symbolic links. A local attacker with access to the swtpm account can replace the logfile with a symlink, causing libvirtd (running as root) to… | |
| Pendiente de análisis | Alta (7.8) | 0.18% | — | LibvirtAI | 20/8/2026 | 21/9/2026 | A flaw was found in libvirt. An unprivileged local user could exploit an integer overflow vulnerability in the NodeGetFreePages RPC handler. This flaw allows crafted values to bypass a size check, leading to an undersized memory buffer. Subsequently, real NUMA node data can overwrite this buffer. This heap buffer… | |
| Pendiente de análisis | Alta (7.8) | 0.18% | — | LibvirtAI | 10/8/2026 | 21/9/2026 | A flaw was found in libvirt. A local attacker, specifically a process running as the confined `swtpm` user, could exploit a symlink-following vulnerability in the `virFileChownFiles()` function. By planting a symbolic link within the `swtpm` state directory, the attacker could trick the root-level libvirt daemon into… | |
| Pendiente de análisis | Media (5.5) | 0.14% | — | LibvirtAIQemu-imgAI | 10/8/2026 | 14/8/2026 | A flaw was found in libvirt. During storage volume clone or convert operations, newly created volume images were temporarily world-readable. This was caused by the `qemu-img` utility running with overly permissive file creation settings, allowing any local user to read the full guest disk contents. This vulnerability… | |
| Pendiente de análisis | Baja (2.3) | 0.16% | — | LibvirtAI | 7/8/2026 | 14/8/2026 | An injection vulnerability was found in libvirt's virtual network driver. The network XML parser does not strip newline characters from DNS TXT record value attributes and SRV record domain/target attributes. These values are written verbatim into the dnsmasq configuration file generated by the network driver,… | |
| Pendiente de análisis | Alta (7.3) | 0.18% | — | Qemu Guest AgentAILibvirtAI | 20/7/2026 | 31/8/2026 | A flaw was found in the QEMU Guest Agent (qga). A local unprivileged user can exploit a vulnerability in the guest-ssh-add-authorized-keys command handler by manipulating symbolic links. This can occur either through a deterministic directory-symlink bypass or a Time-of-Check to Time-of-Use (TOCTOU) file-symlink race.… | |
| Aplazada | Media (5.5) | 0.12% | — | LibvirtAI | 17/11/2025 | 30/6/2026 | A flaw was found in libvirt. External inactive snapshots for shut-down VMs are incorrectly created as world-readable, making it possible for unprivileged users to inspect the guest OS contents. This results in an information disclosure vulnerability. | |
| Aplazada | Media (5.5) | 0.21% | — | LibvirtAI | 11/11/2025 | 30/6/2026 | A flaw was discovered in libvirt in the XML file processing. More specifically, the parsing of user provided XML files was performed before the ACL checks. A malicious user with limited permissions could exploit this flaw by submitting a specially crafted XML file, causing libvirt to allocate too much memory on the… | |
| Modificada | Media (6.2) | 0.24% | — | Redhat Libvirt | 30/8/2024 | 17/6/2026 | A flaw was found in libvirt. A refactor of the code fetching the list of interfaces for multiple APIs introduced a corner case on platforms where allocating 0 bytes of memory results in a NULL pointer. This corner case would lead to a NULL-pointer dereference and subsequent crash of virtinterfaced. This issue could… | |
| Aplazada | Media (6.2) | 0.49% | — | LibvirtAI | 8/5/2024 | 17/6/2026 | A race condition leading to a stack use-after-free flaw was found in libvirt. Due to a bad assumption in the virNetClientIOEventLoop() method, the `data` pointer to a stack-allocated virNetClientIOEventData structure ended up being used in the virNetClientIOEventFD callback while the data pointer's stack frame was… | |
| Aplazada | Media (6.2) | 0.37% | — | LibvirtAI | 21/3/2024 | 17/6/2026 | A flaw was found in the RPC library APIs of libvirt. The RPC server deserialization code allocates memory for arrays before the non-negative length check is performed by the C API entry points. Passing a negative length to the g_new0 function results in a crash due to the negative length being treated as a huge… | |
| Analizada | Media (5.5) | 0.25% | — | Redhat LibvirtRedhat Enterprise LinuxDebian Linux | 18/3/2024 | 17/6/2026 | A NULL pointer dereference flaw was found in the udevConnectListAllInterfaces() function in libvirt. This issue can occur when detaching a host interface while at the same time collecting the list of interfaces via virConnectListAllInterfaces API. This flaw could be used to perform a denial of service attack by… | |
| Aplazada | Media (5.5) | 0.40% | — | LibvirtAI | 11/3/2024 | 17/6/2026 | An off-by-one error flaw was found in the udevListInterfacesByStatus() function in libvirt when the number of interfaces exceeds the size of the `names` array. This issue can be reproduced by sending specially crafted data to the libvirt daemon, allowing an unprivileged client to perform a denial of service attack by… | |
| Modificada | Media (5.3) | 0.76% | — | Redhat LibvirtRedhat Enterprise Linux | 24/7/2023 | 17/6/2026 | A flaw was found in libvirt. The virStoragePoolObjListSearch function does not return a locked pool as expected, resulting in a race condition and denial of service when attempting to lock the same object from another thread. This issue could allow clients connecting to the read-only socket to crash the libvirt daemon. | |
| Modificada | Media (5.5) | 0.25% | — | Redhat LibvirtFedoraproject FedoraRedhat Enterprise Linux | 15/5/2023 | 17/6/2026 | A vulnerability was found in libvirt. This security flaw ouccers due to repeatedly querying an SR-IOV PCI device's capabilities that exposes a memory leak caused by a failure to free the virPCIVirtualFunction array within the parent struct's g_autoptr cleanup. | |
| Modificada | Media (6.5) | 1.5% | — | Redhat LibvirtCanonical Ubuntu LinuxFedoraproject FedoraRedhat Enterprise Linux+10 | 23/8/2022 | 17/6/2026 | A use-after-free flaw was found in libvirt. The qemuMonitorUnregister() function in qemuProcessHandleMonitorEOF is called using multiple threads without being adequately protected by a monitor lock. This flaw could be triggered by the virConnectGetAllDomainStats API when the guest is shutting down. An unprivileged… | |
| Modificada | Media (4.3) | 1.0% | — | Redhat LibvirtNetapp Ontap Select Deploy Administration Utility | 25/3/2022 | 17/6/2026 | A flaw was found in the libvirt nwfilter driver. The virNWFilterObjListNumOfNWFilters method failed to acquire the driver->nwfilters mutex before iterating over virNWFilterObj instances. There was no protection to stop another thread from concurrently modifying the driver->nwfilters object. This flaw allows a… | |
| Modificada | Media (6.5) | 0.24% | — | Redhat LibvirtFedoraproject FedoraNetapp Ontap Select Deploy Administration Utility | 25/3/2022 | 17/6/2026 | A flaw was found in the libvirt libxl driver. A malicious guest could continuously reboot itself and cause libvirtd on the host to deadlock or crash, resulting in a denial of service condition. | |
| Analizada | Media (6.5) | 1.4% | — | Redhat LibvirtRedhat Enterprise LinuxNetapp Ontap Select Deploy Administration UtilityDebian Linux | 2/3/2022 | 17/6/2026 | An improper locking issue was found in the virStoragePoolLookupByTargetPath API of libvirt. It occurs in the storagePoolLookupByTargetPath function where a locked virStoragePoolObj object is not properly released on ACL permission failure. Clients connecting to the read-write socket with limited ACL permissions could… | |
| Modificada | Media (6.3) | 0.49% | — | Redhat LibvirtRedhat Openshift Container PlatformRedhat Enterprise LinuxNetapp Ontap Select Deploy Administration Utility | 2/3/2022 | 17/6/2026 | A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs' dynamic labels. This flaw allows one exploited guest to access files labeled for another guest, resulting in the breaking out of sVirt confinement. The highest threat from this vulnerability is to confidentiality and integrity. | |
| Modificada | Media (6.5) | 1.2% | — | Redhat LibvirtRedhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux FOR IBM Z Systems+9 | 27/5/2021 | 17/6/2026 | An information disclosure vulnerability was found in libvirt in versions before 6.3.0. HTTP cookies used to access network-based disks were saved in the XML dump of the guest domain. This flaw allows an attacker to access potentially sensitive information in the domain configuration via the `dumpxml` command. | |
| Modificada | Media (6.5) | 0.86% | — | Redhat Libvirt | 27/5/2021 | 17/6/2026 | A missing authorization flaw was found in the libvirt API responsible for changing the QEMU agent response timeout. This flaw allows read-only connections to adjust the time that libvirt waits for the QEMU guest agent to respond to agent commands. Depending on the timeout value that is set, this flaw can make guest… | |
| Modificada | Media (6.5) | 1.0% | — | Redhat LibvirtNetapp Ontap Select Deploy Administration Utility | 24/5/2021 | 17/6/2026 | A flaw was found in libvirt in the virConnectListAllNodeDevices API in versions before 7.0.0. It only affects hosts with a PCI device and driver that supports mediated devices (e.g., GRID driver). This flaw could be used by an unprivileged client with a read-only connection to crash the libvirt daemon by executing the… | |
| Modificada | Alta (8.8) | 0.82% | — | Jenkins Libvirt Agents | 18/3/2021 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Libvirt Agents Plugin 1.9.0 and earlier allows attackers to stop hypervisor domains. | |
| Modificada | Alta (8.8) | 0.42% | — | Redhat LibvirtRedhat Enterprise Linux | 3/12/2020 | 17/6/2026 | A flaw was found in libvirt, where it leaked a file descriptor for `/dev/mapper/control` into the QEMU process. This file descriptor allows for privileged operations to happen against the device-mapper on the host. This flaw allows a malicious guest user or process to perform operations outside of their standard… |