Vulnerability CVE-2025-13193: Information
Description
A flaw was found in libvirt. External inactive snapshots for shut-down VMs are incorrectly created as world-readable, making it possible for unprivileged users to inspect the guest OS contents. This results in an information disclosure vulnerability.
Severity: MEDIUM (5.5)
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Fixed packages
Package name | Branch | Fixed in version | Version from repository | Errata ID | Task # | State |
|---|---|---|---|---|---|---|
| libvirt | sisyphus | 11.10.0-alt1 | 11.10.0-alt1 | ALT-PU-2025-15269-2 | 401568 | Fixed |
| libvirt | sisyphus_riscv64 | 11.10.0-alt1 | 11.10.0-alt1 | ALT-PU-2025-15300-1 | - | Fixed |
| libvirt | sisyphus_loongarch64 | 11.10.0-alt1 | 11.10.0-alt1 | ALT-PU-2025-15626-1 | - | Fixed |
| libvirt | p10 | 11.10.0-alt0.c10f2.1 | 9.7.0-alt2.p10.3 | ALT-PU-2025-15732-1 | 401614 | Testing |
| libvirt | c10f2 | 11.10.0-alt0.c10f2.1 | 9.7.0-alt2.p10.3 | ALT-PU-2025-15306-1 | 401592 | Testing |
| libvirt | p11 | 11.10.0-alt1 | 11.10.0-alt1 | ALT-PU-2025-15273-3 | 401580 | Fixed |