USN-8652-1

    Dashboard / Vulnerabilities / USN-8652-1

    USN-8652-1

    Published: 19 Aug 2026Last Modified: 20 Aug 2026

    Summary: libvirt vulnerabilities

    Details: It was discovered that libvirt incorrectly handled guest reboots in the libxl driver. An attacker in a guest could possibly use this issue to cause the libvirt daemon to crash, resulting in a denial of service. This issue only affected Ubuntu 16.04 LTS. (CVE-2021-4147) Alexander Kuznetsov discovered that libvirt incorrectly handled listing network interfaces. An attacker could possibly use this issue to cause the libvirt daemon to crash, resulting in a denial of service. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 18.04 LTS. (CVE-2024-1441) It was discovered that libvirt incorrectly handled certain values in its RPC library. An attacker could possibly use this issue to cause the libvirt daemon to crash, resulting in a denial of service. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 18.04 LTS. (CVE-2024-2494) It was discovered that libvirt incorrectly handled listing network interfaces under certain circumstances. An attacker could possibly use this issue to cause the libvirt daemon to crash, resulting in a denial of service. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 18.04 LTS. (CVE-2024-2496) It was discovered that libvirt incorrectly set permissions on external inactive snapshots, making them world-readable. A local attacker could possibly use this issue to obtain sensitive information. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. (CVE-2025-13193) It was discovered that libvirt incorrectly handled certain characters in virtual network definitions. An authenticated user could possibly use this issue to inject arbitrary configuration directives and execute arbitrary code as root. This issue did not affect Ubuntu 14.04 LTS. (CVE-2026-61477) It was discovered that libvirt incorrectly handled certain XML input. An attacker could possibly use this issue to cause the libvirt daemon to crash, resulting in a denial of service. (CVE-2026-61478) He Wei discovered that libvirt incorrectly followed symbolic links when changing file ownership. A local attacker could possibly use this issue to escalate privileges. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-63622) It was discovered that libvirt incorrectly set permissions on images during storage volume clone and convert operations, making them temporarily world-readable. A local attacker could possibly use this issue to obtain sensitive information. (CVE-2026-63623)

    Affected packages

    Package

    Name: libvirt

    Purl: pkg:deb/ubuntu/libvirt?arch=source&distro=esm-infra-legacy%2Ftrusty

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -1.2.2-0ubuntu13.1.28+esm2

    Affected versions

    1.1.1-0ubuntu8
    1.1.1-0ubuntu9
    1.1.4-0ubuntu2
    1.1.4-0ubuntu3
    1.1.4-0ubuntu4
    1.1.4-0ubuntu5

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    USN-8652-1 | CVE-DB