Vulnerability CVE-2025-13193: Information

Description

A flaw was found in libvirt. External inactive snapshots for shut-down VMs are incorrectly created as world-readable, making it possible for unprivileged users to inspect the guest OS contents. This results in an information disclosure vulnerability.

Severity: MEDIUM (5.5)
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Published: Nov. 17, 2025
Modified: Nov. 18, 2025
Error type identifier: CWE-276

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
libvirtsisyphus11.10.0-alt111.10.0-alt1ALT-PU-2025-15269-2401568Fixed
libvirtsisyphus_riscv6411.10.0-alt111.10.0-alt1ALT-PU-2025-15300-1-Fixed
libvirtsisyphus_loongarch6411.10.0-alt111.10.0-alt1ALT-PU-2025-15626-1-Fixed
libvirtp1011.10.0-alt0.c10f2.19.7.0-alt2.p10.3ALT-PU-2025-15732-1401614Testing
libvirtc10f211.10.0-alt0.c10f2.19.7.0-alt2.p10.3ALT-PU-2025-15306-1401592Testing
libvirtp1111.10.0-alt111.10.0-alt1ALT-PU-2025-15273-3401580Fixed

References to Advisories, Solutions, and Tools