Home / mailingsPDF  

[USN-8833-1] libvirt vulnerabilities

Posted on 28 September 2026
Ubuntu Security

==========================================================================Ubuntu Security Notice USN-8833-1
September 28, 2026

libvirt-hwe vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 26.04 LTS

Summary:

Several security issues were fixed in libvirt.

Software Description:
- libvirt-hwe: Libvirt virtualization toolkit

Details:

It was discovered that libvirt did not properly validate newline characters
in DNS TXT record values and SRV record attributes in its virtual network
driver. A local attacker with permission to define virtual networks could
possibly use this issue to inject arbitrary dnsmasq configuration
directives, leading to arbitrary command execution as root.
(CVE-2026-61477)

It was discovered that libvirt did not properly handle errors during XML
context parsing. An attacker could possibly use this issue to cause libvirt
to crash, resulting in a denial of service. (CVE-2026-61478)

He Wei discovered that libvirt had a symlink-following vulnerability in the
file ownership change function used for virtual TPM state directories. A
local attacker running as the swtpm user could possibly use this issue to
cause libvirt to change the ownership of an arbitrary file, leading to
privilege escalation. (CVE-2026-63622)

It was discovered that libvirt created storage volume images with overly
permissive permissions during clone or convert operations. A local attacker
could possibly use this issue to read guest disk contents, resulting in
information disclosure. (CVE-2026-63623)

It was discovered that libvirt had an integer overflow in the
NodeGetFreePages RPC handler. A local attacker could possibly use this
issue to cause libvirt to crash or execute arbitrary code.
(CVE-2026-18917)

It was discovered that libvirt had a symlink-following flaw in the virtual
TPM emulator setup function. A local attacker with access to the swtpm
account could possibly use this issue to cause libvirt to change the
ownership of an arbitrary file, leading to privilege escalation.
(CVE-2026-77159)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 26.04 LTS
libvirt-daemon-hwe 12.0.0-1ubuntu5.5
libvirt-daemon-system-hwe 12.0.0-1ubuntu5.5
libvirt0-hwe 12.0.0-1ubuntu5.5

After a standard system update you need to reboot your computer to make
all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-8833-1
CVE-2026-18917, CVE-2026-61477, CVE-2026-61478, CVE-2026-63622,
CVE-2026-63623, CVE-2026-77159

Package Information:
https://launchpad.net/ubuntu/+source/libvirt-hwe/12.0.0-1ubuntu5.5

--===============8273938915684854755==Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature

 

TOP