A flaw was found in libvirt. During storage volume clone or convert operations, newly created volume images were temporarily world-readable. This was caused by the `qemu-img` utility running with overly permissive file creation settings, allowing any local user to read the full guest disk contents. This vulnerability could lead to sensitive information disclosure from guest virtual machines.
Metrics
Affected Vendors & Products
References
History
Mon, 10 Aug 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 10 Aug 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in libvirt. During storage volume clone or convert operations, newly created volume images were temporarily world-readable. This was caused by the `qemu-img` utility running with overly permissive file creation settings, allowing any local user to read the full guest disk contents. This vulnerability could lead to sensitive information disclosure from guest virtual machines. | |
| Title | Libvirt: information disclosure via world-readable storage volume images during clone/convert | |
| First Time appeared |
Redhat
Redhat enterprise Linux Redhat enterprise Linux Nvidia |
|
| Weaknesses | CWE-732 | |
| CPEs | cpe:/a:redhat:enterprise_linux_nvidia: cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:6 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux Redhat enterprise Linux Nvidia |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-08-10T21:10:46.846Z
Reserved: 2026-07-17T13:06:13.760Z
Link: CVE-2026-63623
Updated: 2026-08-10T18:30:30.934Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-10T20:15:03Z