← Back

Libvirt

libvirt

Vendor: Redhat • 73 CVEs

CVEs (73)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Canonical
Redhat
5Enterprise Linux
LibvirtUbuntu Linux+2 more
Jun 17, 2026
Jul 30, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
It was discovered that libvirtd before versions 4.10.1 and 5.4.1 would permit read-only clients to use the virDomainSaveImageGetXMLDesc() API, specifying an arbitrary path which would be accessed with the permissions of...Show more
It was discovered that libvirtd before versions 4.10.1 and 5.4.1 would permit read-only clients to use the virDomainSaveImageGetXMLDesc() API, specifying an arbitrary path which would be accessed with the permissions of the libvirtd process. An attacker with access to the libvirtd socket could use this to probe the existence of arbitrary files, cause denial of service or cause libvirtd to execute arbitrary programs.Show less
2Fedoraproject
Redhat
2Fedora
Libvirt
Jun 17, 2026
May 22, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A vulnerability was found in libvirt >= 4.1.0 in the virtlockd-admin.socket and virtlogd-admin.socket systemd units. A missing SocketMode configuration parameter allows any user on the host to connect using virtlockd-adm...Show more
A vulnerability was found in libvirt >= 4.1.0 in the virtlockd-admin.socket and virtlogd-admin.socket systemd units. A missing SocketMode configuration parameter allows any user on the host to connect using virtlockd-admin-sock or virtlogd-admin-sock and perform administrative tasks against the virtlockd and virtlogd daemons.Show less
2Debian
Redhat
2Debian Linux
Libvirt
Nov 21, 2024
Apr 18, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
libvirt-domain.c in libvirt before 1.3.1 supports virDomainGetTime API calls by guest agents with an RO connection, even though an RW connection was supposed to be required, a different vulnerability than CVE-2019-3886.
3Fedoraproject
OpensuseRedhat
3Fedora
LeapLibvirt
Jun 17, 2026
Apr 4, 2019
N/A· v4
5.4 MEDIUM· v3
4.8 MEDIUM· v2
An incorrect permissions check was discovered in libvirt 4.8.0 and above. The readonly permission was allowed to invoke APIs depending on the guest agent, which could lead to potentially disclosing unintended information...Show more
An incorrect permissions check was discovered in libvirt 4.8.0 and above. The readonly permission was allowed to invoke APIs depending on the guest agent, which could lead to potentially disclosing unintended information or denial of service by causing libvirt to block.Show less
2Opensuse
Redhat
2Leap
Libvirt
Jun 17, 2026
Mar 27, 2019
N/A· v4
6.3 MEDIUM· v3
3.5 LOW· v2
A NULL pointer dereference flaw was discovered in libvirt before version 5.0.0 in the way it gets interface information through the QEMU agent. An attacker in a guest VM can use this flaw to crash libvirtd and cause a de...Show more
A NULL pointer dereference flaw was discovered in libvirt before version 5.0.0 in the way it gets interface information through the QEMU agent. An attacker in a guest VM can use this flaw to crash libvirtd and cause a denial of service.Show less
1Redhat
1Libvirt
Nov 21, 2024
Aug 22, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A NULL pointer deference flaw was found in the way libvirt from 2.5.0 to 3.0.0 handled empty drives. A remote authenticated attacker could use this flaw to crash libvirtd daemon resulting in denial of service.
2Debian
Redhat
2Debian Linux
Libvirt
Nov 21, 2024
Mar 28, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
libvirt version before 4.2.0-rc1 is vulnerable to a resource exhaustion as a result of an incomplete fix for CVE-2018-5748 that affects QEMU monitor but now also triggered via QEMU guest agent.
3Canonical
DebianRedhat
7Debian Linux
Enterprise Linux DesktopEnterprise Linux Server+4 more
Jun 17, 2026
Feb 23, 2018
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
util/virlog.c in libvirt does not properly determine the hostname on LXC container startup, which allows local guest OS users to bypass an intended container protection mechanism and execute arbitrary commands via a craf...Show more
util/virlog.c in libvirt does not properly determine the hostname on LXC container startup, which allows local guest OS users to bypass an intended container protection mechanism and execute arbitrary commands via a crafted NSS module.Show less
2Debian
Redhat
8Debian Linux
Enterprise Linux DesktopEnterprise Linux Server+5 more
Jun 17, 2026
Jan 25, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
qemu/qemu_monitor.c in libvirt allows attackers to cause a denial of service (memory consumption) via a large QEMU reply.
2Debian
Redhat
2Debian Linux
Libvirt
May 13, 2026
Oct 31, 2017
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
libvirt version 2.3.0 and later is vulnerable to a bad default configuration of "verify-peer=no" passed to QEMU by libvirt resulting in a failure to validate SSL/TLS certificates by default.
2Debian
Redhat
2Debian Linux
Libvirt
May 6, 2026
Jul 13, 2016
N/A· v4
9.8 CRITICAL· v3
4.3 MEDIUM· v2
libvirt before 2.0.0 improperly disables password checking when the password on a VNC server is set to an empty string, which allows remote attackers to bypass authentication and establish a VNC session by connecting to...Show more
libvirt before 2.0.0 improperly disables password checking when the password on a VNC server is set to an empty string, which allows remote attackers to bypass authentication and establish a VNC session by connecting to the server.Show less
2Redhat
Xen
2Libvirt
Xen
May 6, 2026
May 25, 2016
N/A· v4
6.5 MEDIUM· v3
2.1 LOW· v2
The qemu implementation in libvirt before 1.3.0 and Xen allows local guest OS users to cause a denial of service (host disk consumption) by writing to stdout or stderr.
2Canonical
Redhat
2Libvirt
Ubuntu Linux
May 6, 2026
Apr 14, 2016
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The virStorageVolCreateXML API in libvirt 1.2.14 through 1.2.19 allows remote authenticated users with a read-write connection to cause a denial of service (libvirtd crash) by triggering a failed unlink after creating a...Show more
The virStorageVolCreateXML API in libvirt 1.2.14 through 1.2.19 allows remote authenticated users with a read-write connection to cause a denial of service (libvirtd crash) by triggering a failed unlink after creating a volume on a root_squash NFS pool.Show less
2Canonical
Redhat
2Libvirt
Ubuntu Linux
May 6, 2026
Apr 14, 2016
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The networkReloadIptablesRules function in network/bridge_driver.c in libvirt before 0.9.9 does not properly handle firewall rules on bridge networks when libvirtd is restarted, which might allow remote attackers to bypa...Show more
The networkReloadIptablesRules function in network/bridge_driver.c in libvirt before 0.9.9 does not properly handle firewall rules on bridge networks when libvirtd is restarted, which might allow remote attackers to bypass intended access restrictions via a (1) DNS or (2) DHCP query.Show less
1Redhat
1Libvirt
May 6, 2026
Apr 11, 2016
N/A· v4
2.5 LOW· v3
1.9 LOW· v2
Directory traversal vulnerability in the virStorageBackendFileSystemVolCreate function in storage/storage_backend_fs.c in libvirt, when fine-grained Access Control Lists (ACL) are in effect, allows local users with stora...Show more
Directory traversal vulnerability in the virStorageBackendFileSystemVolCreate function in storage/storage_backend_fs.c in libvirt, when fine-grained Access Control Lists (ACL) are in effect, allows local users with storage_vol:create ACL but not domain:write permission to write to arbitrary files via a .. (dot dot) in a volume name.Show less
3Canonical
MageiaRedhat
7Enterprise Linux Desktop
Enterprise Linux Hpc NodeEnterprise Linux Server+4 more
May 6, 2026
Jan 29, 2015
N/A· v4
N/A· v3
3.5 LOW· v2
libvirt before 1.2.12 allow remote authenticated users to obtain the VNC password by using the VIR_DOMAIN_XML_SECURE flag with a crafted (1) snapshot to the virDomainSnapshotGetXMLDesc interface or (2) image to the virDo...Show more
libvirt before 1.2.12 allow remote authenticated users to obtain the VNC password by using the VIR_DOMAIN_XML_SECURE flag with a crafted (1) snapshot to the virDomainSnapshotGetXMLDesc interface or (2) image to the virDomainSaveImageGetXMLDesc interface.Show less
1Redhat
1Libvirt
May 6, 2026
Jan 6, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The qemu implementation of virConnectGetAllDomainStats in libvirt before 1.2.11 does not properly handle locks when a domain is skipped due to ACL restrictions, which allows a remote authenticated users to cause a denial...Show more
The qemu implementation of virConnectGetAllDomainStats in libvirt before 1.2.11 does not properly handle locks when a domain is skipped due to ACL restrictions, which allows a remote authenticated users to cause a denial of service (deadlock or segmentation fault and crash) via a request to access the users does not have privileges to access.Show less
4Canonical
MageiaOpensuse+1 more
8Enterprise Linux Desktop
Enterprise Linux Hpc NodeEnterprise Linux Server+5 more
May 6, 2026
Dec 19, 2014
N/A· v4
N/A· v3
2.1 LOW· v2
The (1) qemuDomainMigratePerform and (2) qemuDomainMigrateFinish2 functions in qemu/qemu_driver.c in libvirt do not unlock the domain when an ACL check fails, which allow local users to cause a denial of service via unsp...Show more
The (1) qemuDomainMigratePerform and (2) qemuDomainMigrateFinish2 functions in qemu/qemu_driver.c in libvirt do not unlock the domain when an ACL check fails, which allow local users to cause a denial of service via unspecified vectors.Show less
1Redhat
1Libvirt
May 6, 2026
Dec 19, 2014
N/A· v4
N/A· v3
2.1 LOW· v2
The storageVolUpload function in storage/storage_driver.c in libvirt before 1.2.11 does not check a certain return value, which allows local users to cause a denial of service (NULL pointer dereference and daemon crash)...Show more
The storageVolUpload function in storage/storage_driver.c in libvirt before 1.2.11 does not check a certain return value, which allows local users to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted offset value in a "virsh vol-upload" command.Show less
1Redhat
1Libvirt
May 6, 2026
Dec 12, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The remoteClientFreeFunc function in daemon/remote.c in libvirt before 1.1.3, when ACLs are used, does not set an identity, which causes event handler removal to be denied and remote attackers to cause a denial of servic...Show more
The remoteClientFreeFunc function in daemon/remote.c in libvirt before 1.1.3, when ACLs are used, does not set an identity, which causes event handler removal to be denied and remote attackers to cause a denial of service (use-after-free and crash) by registering an event handler and then closing the connection.Show less