Vulnerability CVE-2025-12748: Information

Description

A flaw was discovered in libvirt in the XML file processing. More specifically, the parsing of user provided XML files was performed before the ACL checks. A malicious user with limited permissions could exploit this flaw by submitting a specially crafted XML file, causing libvirt to allocate too much memory on the host. The excessive memory consumption could lead to a libvirt process crash on the host, resulting in a denial-of-service condition.

Severity: MEDIUM (5.5)
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Published: Nov. 11, 2025
Modified: Nov. 12, 2025
Error type identifier: CWE-770

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
libvirtsisyphus11.10.0-alt111.10.0-alt1ALT-PU-2025-15269-2401568Fixed
libvirtsisyphus_riscv6411.10.0-alt111.10.0-alt1ALT-PU-2025-15300-1-Fixed
libvirtsisyphus_loongarch6411.10.0-alt111.10.0-alt1ALT-PU-2025-15626-1-Fixed
libvirtp1011.10.0-alt0.c10f2.19.7.0-alt2.p10.3ALT-PU-2025-15732-1401614Testing
libvirtc10f211.10.0-alt0.c10f2.19.7.0-alt2.p10.3ALT-PU-2025-15306-1401592Testing
libvirtp1111.10.0-alt111.10.0-alt1ALT-PU-2025-15273-3401580Fixed

References to Advisories, Solutions, and Tools