USN-8833-1: libvirt vulnerabilities

Publication date

28 September 2026

Overview

Several security issues were fixed in libvirt.

Releases


Packages

Details

It was discovered that libvirt did not properly validate newline characters
in DNS TXT record values and SRV record attributes in its virtual network
driver. A local attacker with permission to define virtual networks could
possibly use this issue to inject arbitrary dnsmasq configuration
directives, leading to arbitrary command execution as root.
(CVE-2026-61477)

It was discovered that libvirt did not properly handle errors during XML
context parsing. An attacker could possibly use this issue to cause libvirt
to crash, resulting in a denial of service. (CVE-2026-61478)

He Wei discovered that libvirt had a symlink-following vulnerability in the
file ownership change function used for virtual TPM state directories. A
local attacker running as the swtpm user could possibly use this issue to
cause libvirt to change the ownership of an arbitrary file,...

It was discovered that libvirt did not properly validate newline characters
in DNS TXT record values and SRV record attributes in its virtual network
driver. A local attacker with permission to define virtual networks could
possibly use this issue to inject arbitrary dnsmasq configuration
directives, leading to arbitrary command execution as root.
(CVE-2026-61477)

It was discovered that libvirt did not properly handle errors during XML
context parsing. An attacker could possibly use this issue to cause libvirt
to crash, resulting in a denial of service. (CVE-2026-61478)

He Wei discovered that libvirt had a symlink-following vulnerability in the
file ownership change function used for virtual TPM state directories. A
local attacker running as the swtpm user could possibly use this issue to
cause libvirt to change the ownership of an arbitrary file, leading to
privilege escalation. (CVE-2026-63622)

It was discovered that libvirt created storage volume images with overly
permissive permissions during clone or convert operations. A local attacker
could possibly use this issue to read guest disk contents, resulting in
information disclosure. (CVE-2026-63623)

It was discovered that libvirt had an integer overflow in the
NodeGetFreePages RPC handler. A local attacker could possibly use this
issue to cause libvirt to crash or execute arbitrary code.
(CVE-2026-18917)

It was discovered that libvirt had a symlink-following flaw in the virtual
TPM emulator setup function. A local attacker with access to the swtpm
account could possibly use this issue to cause libvirt to change the
ownership of an arbitrary file, leading to privilege escalation.
(CVE-2026-77159)


Update instructions

After a standard system update you need to reboot your computer to make all the necessary changes.

Learn more about how to get the fixes.

The problem can be corrected by updating your system to the following package versions:

Ubuntu Release Package Version
26.04 LTS resolute libvirt-daemon-hwe –  12.0.0-1ubuntu5.5
libvirt-daemon-system-hwe –  12.0.0-1ubuntu5.5
libvirt0-hwe –  12.0.0-1ubuntu5.5

Reduce your security exposure

Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.


Have additional questions?

Talk to a member of the team ›