Bugs fixes in "libvirt-hwe"
| Origin | Bug number | Title | Date fixed |
|---|---|---|---|
| CVE | CVE-2026-77159 | A symlink-following flaw was found in libvirt's qemuTPMEmulatorPrepareHost() function. The function uses a path-based chown() on the swtpm logfile wi | 2026-09-28 |
| CVE | CVE-2026-18917 | A flaw was found in libvirt. An unprivileged local user could exploit an integer overflow vulnerability in the NodeGetFreePages RPC handler. This fla | 2026-09-28 |
| CVE | CVE-2026-63623 | A flaw was found in libvirt. During storage volume clone or convert operations, newly created volume images were temporarily world-readable. This was | 2026-09-28 |
| CVE | CVE-2026-63622 | A flaw was found in libvirt. A local attacker, specifically a process running as the confined `swtpm` user, could exploit a symlink-following vulnera | 2026-09-28 |
| CVE | CVE-2026-61477 | An injection vulnerability was found in libvirt's virtual network driver. The network XML parser does not strip newline characters from DNS TXT recor | 2026-09-28 |
| CVE | CVE-2026-77159 | A symlink-following flaw was found in libvirt's qemuTPMEmulatorPrepareHost() function. The function uses a path-based chown() on the swtpm logfile wi | 2026-09-28 |
| CVE | CVE-2026-18917 | A flaw was found in libvirt. An unprivileged local user could exploit an integer overflow vulnerability in the NodeGetFreePages RPC handler. This fla | 2026-09-28 |
| CVE | CVE-2026-63623 | A flaw was found in libvirt. During storage volume clone or convert operations, newly created volume images were temporarily world-readable. This was | 2026-09-28 |
| CVE | CVE-2026-63622 | A flaw was found in libvirt. A local attacker, specifically a process running as the confined `swtpm` user, could exploit a symlink-following vulnera | 2026-09-28 |
| CVE | CVE-2026-61477 | An injection vulnerability was found in libvirt's virtual network driver. The network XML parser does not strip newline characters from DNS TXT recor | 2026-09-28 |
| CVE | CVE-2026-77159 | A symlink-following flaw was found in libvirt's qemuTPMEmulatorPrepareHost() function. The function uses a path-based chown() on the swtpm logfile wi | 2026-09-28 |
| CVE | CVE-2026-18917 | A flaw was found in libvirt. An unprivileged local user could exploit an integer overflow vulnerability in the NodeGetFreePages RPC handler. This fla | 2026-09-28 |
| CVE | CVE-2026-63623 | A flaw was found in libvirt. During storage volume clone or convert operations, newly created volume images were temporarily world-readable. This was | 2026-09-28 |
| CVE | CVE-2026-63622 | A flaw was found in libvirt. A local attacker, specifically a process running as the confined `swtpm` user, could exploit a symlink-following vulnera | 2026-09-28 |
| CVE | CVE-2026-61477 | An injection vulnerability was found in libvirt's virtual network driver. The network XML parser does not strip newline characters from DNS TXT recor | 2026-09-28 |
| CVE | CVE-2026-77159 | A symlink-following flaw was found in libvirt's qemuTPMEmulatorPrepareHost() function. The function uses a path-based chown() on the swtpm logfile wi | 2026-09-28 |
| CVE | CVE-2026-18917 | A flaw was found in libvirt. An unprivileged local user could exploit an integer overflow vulnerability in the NodeGetFreePages RPC handler. This fla | 2026-09-28 |
| CVE | CVE-2026-63623 | A flaw was found in libvirt. During storage volume clone or convert operations, newly created volume images were temporarily world-readable. This was | 2026-09-28 |
| CVE | CVE-2026-63622 | A flaw was found in libvirt. A local attacker, specifically a process running as the confined `swtpm` user, could exploit a symlink-following vulnera | 2026-09-28 |
| CVE | CVE-2026-61477 | An injection vulnerability was found in libvirt's virtual network driver. The network XML parser does not strip newline characters from DNS TXT recor | 2026-09-28 |
About
-
Send Feedback to @ubuntu_updates