Executive brief
libvirt is virtualization management software that handles storage operations for virtual machines. During storage volume cloning or conversion operations, newly created disk images were temporarily readable by any local user on the system, potentially exposing sensitive guest data. This could allow unauthorized access to confidential information stored within virtual machines.
Technical details
A permission assignment vulnerability (CWE-732) in libvirt's storage volume clone and convert operations caused newly created volume images to be world-readable. The root cause is overly permissive file creation settings in the qemu-img utility when run by libvirt. An attacker with local system access can exploit this during the brief window when the volume is being created to read the full contents of guest disk images, leading to information disclosure. The vulnerability requires local access and low privileges. A patch is available through Red Hat updates.
Affected products
- libvirt.org libvirt <UNKNOWN>
Timeline
- 2026-08-10: disclosed
- 2026-08-10: advisory