Executive brief
A security flaw was found in libvirt, a tool used to manage virtualization platforms. When snapshots are created for virtual machines that are powered off, the resulting files are set with incorrect permissions that allow any user on the host system to read them. This could allow an unauthorized person to access sensitive data stored within the virtual machine's operating system.
Technical details
A vulnerability classified as Incorrect Default Permissions (CWE-276) exists in libvirt. When creating external inactive snapshots for virtual machines in a shut-down state, the software fails to restrict file permissions, resulting in world-readable snapshot files. A local, unprivileged attacker can exploit this to read the disk image contents of the guest OS, bypassing intended isolation boundaries. The issue is addressed in libvirt version 11.10.0 and via upstream patches.
Affected products
- libvirt libvirt < 11.10.0
- Red Hat Red Hat Enterprise Linux 8
- Red Hat Red Hat Enterprise Linux 9
- Red Hat Red Hat Enterprise Linux 10
- Red Hat Red Hat In-Vehicle Operating System 1
Timeline
- 2025-11-17: disclosed: Initial report and CVE assignment
- 2025-11-17: advisory: NVD and Red Hat advisories published