USN-8652-1

Source
https://ubuntu.com/security/notices/USN-8652-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8652-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/USN-8652-1
Upstream
Related
Published
2026-08-19T16:56:44Z
Modified
2026-08-20T05:29:53Z
Summary
libvirt vulnerabilities
Details

It was discovered that libvirt incorrectly handled guest reboots in the libxl driver. An attacker in a guest could possibly use this issue to cause the libvirt daemon to crash, resulting in a denial of service. This issue only affected Ubuntu 16.04 LTS. (CVE-2021-4147)

Alexander Kuznetsov discovered that libvirt incorrectly handled listing network interfaces. An attacker could possibly use this issue to cause the libvirt daemon to crash, resulting in a denial of service. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 18.04 LTS. (CVE-2024-1441)

It was discovered that libvirt incorrectly handled certain values in its RPC library. An attacker could possibly use this issue to cause the libvirt daemon to crash, resulting in a denial of service. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 18.04 LTS. (CVE-2024-2494)

It was discovered that libvirt incorrectly handled listing network interfaces under certain circumstances. An attacker could possibly use this issue to cause the libvirt daemon to crash, resulting in a denial of service. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 18.04 LTS. (CVE-2024-2496)

It was discovered that libvirt incorrectly set permissions on external inactive snapshots, making them world-readable. A local attacker could possibly use this issue to obtain sensitive information. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. (CVE-2025-13193)

It was discovered that libvirt incorrectly handled certain characters in virtual network definitions. An authenticated user could possibly use this issue to inject arbitrary configuration directives and execute arbitrary code as root. This issue did not affect Ubuntu 14.04 LTS. (CVE-2026-61477)

It was discovered that libvirt incorrectly handled certain XML input. An attacker could possibly use this issue to cause the libvirt daemon to crash, resulting in a denial of service. (CVE-2026-61478)

He Wei discovered that libvirt incorrectly followed symbolic links when changing file ownership. A local attacker could possibly use this issue to escalate privileges. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-63622)

It was discovered that libvirt incorrectly set permissions on images during storage volume clone and convert operations, making them temporarily world-readable. A local attacker could possibly use this issue to obtain sensitive information. (CVE-2026-63623)

References

Affected packages

Ubuntu:22.04:LTS
libvirt

Package

Name
libvirt
Purl
pkg:deb/ubuntu/libvirt?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
8.0.0-1ubuntu7.19

Affected versions

7.*
7.6.0-0ubuntu1
7.6.0-0ubuntu3
8.*
8.0.0-1ubuntu3
8.0.0-1ubuntu4
8.0.0-1ubuntu5
8.0.0-1ubuntu6
8.0.0-1ubuntu7
8.0.0-1ubuntu7.1
8.0.0-1ubuntu7.2
8.0.0-1ubuntu7.3
8.0.0-1ubuntu7.4
8.0.0-1ubuntu7.5
8.0.0-1ubuntu7.6
8.0.0-1ubuntu7.7
8.0.0-1ubuntu7.8
8.0.0-1ubuntu7.9
8.0.0-1ubuntu7.10
8.0.0-1ubuntu7.11
8.0.0-1ubuntu7.12
8.0.0-1ubuntu7.13
8.0.0-1ubuntu7.14
8.0.0-1ubuntu7.15
8.0.0-1ubuntu7.16
8.0.0-1ubuntu7.17
8.0.0-1ubuntu7.18

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "libnss-libvirt",
            "binary_version": "8.0.0-1ubuntu7.19"
        },
        {
            "binary_name": "libvirt-clients",
            "binary_version": "8.0.0-1ubuntu7.19"
        },
        {
            "binary_name": "libvirt-daemon",
            "binary_version": "8.0.0-1ubuntu7.19"
        },
        {
            "binary_name": "libvirt-daemon-config-network",
            "binary_version": "8.0.0-1ubuntu7.19"
        },
        {
            "binary_name": "libvirt-daemon-config-nwfilter",
            "binary_version": "8.0.0-1ubuntu7.19"
        },
        {
            "binary_name": "libvirt-daemon-driver-lxc",
            "binary_version": "8.0.0-1ubuntu7.19"
        },
        {
            "binary_name": "libvirt-daemon-driver-qemu",
            "binary_version": "8.0.0-1ubuntu7.19"
        },
        {
            "binary_name": "libvirt-daemon-driver-storage-gluster",
            "binary_version": "8.0.0-1ubuntu7.19"
        },
        {
            "binary_name": "libvirt-daemon-driver-storage-iscsi-direct",
            "binary_version": "8.0.0-1ubuntu7.19"
        },
        {
            "binary_name": "libvirt-daemon-driver-storage-rbd",
            "binary_version": "8.0.0-1ubuntu7.19"
        },
        {
            "binary_name": "libvirt-daemon-driver-storage-zfs",
            "binary_version": "8.0.0-1ubuntu7.19"
        },
        {
            "binary_name": "libvirt-daemon-driver-vbox",
            "binary_version": "8.0.0-1ubuntu7.19"
        },
        {
            "binary_name": "libvirt-daemon-driver-xen",
            "binary_version": "8.0.0-1ubuntu7.19"
        },
        {
            "binary_name": "libvirt-daemon-system",
            "binary_version": "8.0.0-1ubuntu7.19"
        },
        {
            "binary_name": "libvirt-daemon-system-systemd",
            "binary_version": "8.0.0-1ubuntu7.19"
        },
        {
            "binary_name": "libvirt-daemon-system-sysv",
            "binary_version": "8.0.0-1ubuntu7.19"
        },
        {
            "binary_name": "libvirt-login-shell",
            "binary_version": "8.0.0-1ubuntu7.19"
        },
        {
            "binary_name": "libvirt-sanlock",
            "binary_version": "8.0.0-1ubuntu7.19"
        },
        {
            "binary_name": "libvirt-wireshark",
            "binary_version": "8.0.0-1ubuntu7.19"
        },
        {
            "binary_name": "libvirt0",
            "binary_version": "8.0.0-1ubuntu7.19"
        }
    ]
}

Database specific

cves_map
{
    "cves": [
        {
            "id": "CVE-2026-61477",
            "severity": [
                {
                    "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N",
                    "type": "CVSS_V3"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2026-61478",
            "severity": [
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2026-63622",
            "severity": [
                {
                    "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "type": "CVSS_V3"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2026-63623",
            "severity": [
                {
                    "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
                    "type": "CVSS_V3"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        }
    ],
    "ecosystem": "Ubuntu:22.04:LTS"
}
source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8652-1.json"
Ubuntu:24.04:LTS
libvirt

Package

Name
libvirt
Purl
pkg:deb/ubuntu/libvirt?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
10.0.0-2ubuntu8.16

Affected versions

9.*
9.6.0-1ubuntu1
9.6.0-1ubuntu2
10.*
10.0.0-1ubuntu1
10.0.0-2ubuntu1
10.0.0-2ubuntu5
10.0.0-2ubuntu7
10.0.0-2ubuntu8
10.0.0-2ubuntu8.1
10.0.0-2ubuntu8.2
10.0.0-2ubuntu8.3
10.0.0-2ubuntu8.4
10.0.0-2ubuntu8.5
10.0.0-2ubuntu8.6
10.0.0-2ubuntu8.7
10.0.0-2ubuntu8.8
10.0.0-2ubuntu8.9
10.0.0-2ubuntu8.10
10.0.0-2ubuntu8.11
10.0.0-2ubuntu8.12
10.0.0-2ubuntu8.13
10.0.0-2ubuntu8.14
10.0.0-2ubuntu8.15

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "libnss-libvirt",
            "binary_version": "10.0.0-2ubuntu8.16"
        },
        {
            "binary_name": "libvirt-clients",
            "binary_version": "10.0.0-2ubuntu8.16"
        },
        {
            "binary_name": "libvirt-clients-qemu",
            "binary_version": "10.0.0-2ubuntu8.16"
        },
        {
            "binary_name": "libvirt-daemon",
            "binary_version": "10.0.0-2ubuntu8.16"
        },
        {
            "binary_name": "libvirt-daemon-config-network",
            "binary_version": "10.0.0-2ubuntu8.16"
        },
        {
            "binary_name": "libvirt-daemon-config-nwfilter",
            "binary_version": "10.0.0-2ubuntu8.16"
        },
        {
            "binary_name": "libvirt-daemon-driver-lxc",
            "binary_version": "10.0.0-2ubuntu8.16"
        },
        {
            "binary_name": "libvirt-daemon-driver-qemu",
            "binary_version": "10.0.0-2ubuntu8.16"
        },
        {
            "binary_name": "libvirt-daemon-driver-storage-gluster",
            "binary_version": "10.0.0-2ubuntu8.16"
        },
        {
            "binary_name": "libvirt-daemon-driver-storage-iscsi-direct",
            "binary_version": "10.0.0-2ubuntu8.16"
        },
        {
            "binary_name": "libvirt-daemon-driver-storage-rbd",
            "binary_version": "10.0.0-2ubuntu8.16"
        },
        {
            "binary_name": "libvirt-daemon-driver-storage-zfs",
            "binary_version": "10.0.0-2ubuntu8.16"
        },
        {
            "binary_name": "libvirt-daemon-driver-vbox",
            "binary_version": "10.0.0-2ubuntu8.16"
        },
        {
            "binary_name": "libvirt-daemon-driver-xen",
            "binary_version": "10.0.0-2ubuntu8.16"
        },
        {
            "binary_name": "libvirt-daemon-system",
            "binary_version": "10.0.0-2ubuntu8.16"
        },
        {
            "binary_name": "libvirt-daemon-system-systemd",
            "binary_version": "10.0.0-2ubuntu8.16"
        },
        {
            "binary_name": "libvirt-daemon-system-sysv",
            "binary_version": "10.0.0-2ubuntu8.16"
        },
        {
            "binary_name": "libvirt-l10n",
            "binary_version": "10.0.0-2ubuntu8.16"
        },
        {
            "binary_name": "libvirt-login-shell",
            "binary_version": "10.0.0-2ubuntu8.16"
        },
        {
            "binary_name": "libvirt-sanlock",
            "binary_version": "10.0.0-2ubuntu8.16"
        },
        {
            "binary_name": "libvirt-wireshark",
            "binary_version": "10.0.0-2ubuntu8.16"
        },
        {
            "binary_name": "libvirt0",
            "binary_version": "10.0.0-2ubuntu8.16"
        }
    ]
}

Database specific

cves_map
{
    "cves": [
        {
            "id": "CVE-2026-61477",
            "severity": [
                {
                    "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N",
                    "type": "CVSS_V3"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2026-61478",
            "severity": [
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2026-63622",
            "severity": [
                {
                    "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "type": "CVSS_V3"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2026-63623",
            "severity": [
                {
                    "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
                    "type": "CVSS_V3"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        }
    ],
    "ecosystem": "Ubuntu:24.04:LTS"
}
source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8652-1.json"
Ubuntu:26.04:LTS
libvirt

Package

Name
libvirt
Purl
pkg:deb/ubuntu/libvirt?arch=source&distro=resolute

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
12.0.0-1ubuntu5.3

Affected versions

11.*
11.6.0-1ubuntu3
11.6.0-1ubuntu5
11.6.0-1ubuntu6
11.6.0-1ubuntu7
11.6.0-1ubuntu8
12.*
12.0.0-1ubuntu3
12.0.0-1ubuntu5
12.0.0-1ubuntu5.1
12.0.0-1ubuntu5.2

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "libnss-libvirt",
            "binary_version": "12.0.0-1ubuntu5.3"
        },
        {
            "binary_name": "libvirt-clients",
            "binary_version": "12.0.0-1ubuntu5.3"
        },
        {
            "binary_name": "libvirt-clients-qemu",
            "binary_version": "12.0.0-1ubuntu5.3"
        },
        {
            "binary_name": "libvirt-common",
            "binary_version": "12.0.0-1ubuntu5.3"
        },
        {
            "binary_name": "libvirt-daemon",
            "binary_version": "12.0.0-1ubuntu5.3"
        },
        {
            "binary_name": "libvirt-daemon-common",
            "binary_version": "12.0.0-1ubuntu5.3"
        },
        {
            "binary_name": "libvirt-daemon-config-network",
            "binary_version": "12.0.0-1ubuntu5.3"
        },
        {
            "binary_name": "libvirt-daemon-config-nwfilter",
            "binary_version": "12.0.0-1ubuntu5.3"
        },
        {
            "binary_name": "libvirt-daemon-driver-interface",
            "binary_version": "12.0.0-1ubuntu5.3"
        },
        {
            "binary_name": "libvirt-daemon-driver-lxc",
            "binary_version": "12.0.0-1ubuntu5.3"
        },
        {
            "binary_name": "libvirt-daemon-driver-network",
            "binary_version": "12.0.0-1ubuntu5.3"
        },
        {
            "binary_name": "libvirt-daemon-driver-nodedev",
            "binary_version": "12.0.0-1ubuntu5.3"
        },
        {
            "binary_name": "libvirt-daemon-driver-nwfilter",
            "binary_version": "12.0.0-1ubuntu5.3"
        },
        {
            "binary_name": "libvirt-daemon-driver-qemu",
            "binary_version": "12.0.0-1ubuntu5.3"
        },
        {
            "binary_name": "libvirt-daemon-driver-secret",
            "binary_version": "12.0.0-1ubuntu5.3"
        },
        {
            "binary_name": "libvirt-daemon-driver-storage",
            "binary_version": "12.0.0-1ubuntu5.3"
        },
        {
            "binary_name": "libvirt-daemon-driver-storage-disk",
            "binary_version": "12.0.0-1ubuntu5.3"
        },
        {
            "binary_name": "libvirt-daemon-driver-storage-gluster",
            "binary_version": "12.0.0-1ubuntu5.3"
        },
        {
            "binary_name": "libvirt-daemon-driver-storage-iscsi",
            "binary_version": "12.0.0-1ubuntu5.3"
        },
        {
            "binary_name": "libvirt-daemon-driver-storage-iscsi-direct",
            "binary_version": "12.0.0-1ubuntu5.3"
        },
        {
            "binary_name": "libvirt-daemon-driver-storage-logical",
            "binary_version": "12.0.0-1ubuntu5.3"
        },
        {
            "binary_name": "libvirt-daemon-driver-storage-mpath",
            "binary_version": "12.0.0-1ubuntu5.3"
        },
        {
            "binary_name": "libvirt-daemon-driver-storage-rbd",
            "binary_version": "12.0.0-1ubuntu5.3"
        },
        {
            "binary_name": "libvirt-daemon-driver-storage-scsi",
            "binary_version": "12.0.0-1ubuntu5.3"
        },
        {
            "binary_name": "libvirt-daemon-driver-storage-zfs",
            "binary_version": "12.0.0-1ubuntu5.3"
        },
        {
            "binary_name": "libvirt-daemon-driver-vbox",
            "binary_version": "12.0.0-1ubuntu5.3"
        },
        {
            "binary_name": "libvirt-daemon-driver-xen",
            "binary_version": "12.0.0-1ubuntu5.3"
        },
        {
            "binary_name": "libvirt-daemon-lock",
            "binary_version": "12.0.0-1ubuntu5.3"
        },
        {
            "binary_name": "libvirt-daemon-log",
            "binary_version": "12.0.0-1ubuntu5.3"
        },
        {
            "binary_name": "libvirt-daemon-plugin-lockd",
            "binary_version": "12.0.0-1ubuntu5.3"
        },
        {
            "binary_name": "libvirt-daemon-plugin-sanlock",
            "binary_version": "12.0.0-1ubuntu5.3"
        },
        {
            "binary_name": "libvirt-daemon-system",
            "binary_version": "12.0.0-1ubuntu5.3"
        },
        {
            "binary_name": "libvirt-daemon-system-systemd",
            "binary_version": "12.0.0-1ubuntu5.3"
        },
        {
            "binary_name": "libvirt-daemon-system-sysv",
            "binary_version": "12.0.0-1ubuntu5.3"
        },
        {
            "binary_name": "libvirt-l10n",
            "binary_version": "12.0.0-1ubuntu5.3"
        },
        {
            "binary_name": "libvirt-login-shell",
            "binary_version": "12.0.0-1ubuntu5.3"
        },
        {
            "binary_name": "libvirt-sanlock",
            "binary_version": "12.0.0-1ubuntu5.3"
        },
        {
            "binary_name": "libvirt-ssh-proxy",
            "binary_version": "12.0.0-1ubuntu5.3"
        },
        {
            "binary_name": "libvirt-wireshark",
            "binary_version": "12.0.0-1ubuntu5.3"
        },
        {
            "binary_name": "libvirt0",
            "binary_version": "12.0.0-1ubuntu5.3"
        }
    ]
}

Database specific

cves_map
{
    "cves": [
        {
            "id": "CVE-2026-61477",
            "severity": [
                {
                    "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N",
                    "type": "CVSS_V3"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2026-61478",
            "severity": [
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2026-63622",
            "severity": [
                {
                    "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "type": "CVSS_V3"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2026-63623",
            "severity": [
                {
                    "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
                    "type": "CVSS_V3"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        }
    ],
    "ecosystem": "Ubuntu:26.04:LTS"
}
source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8652-1.json"
Ubuntu:Pro:14.04:LTS
libvirt

Package

Name
libvirt
Purl
pkg:deb/ubuntu/libvirt?arch=source&distro=esm-infra-legacy%2Ftrusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.2.2-0ubuntu13.1.28+esm2

Affected versions

1.*
1.1.1-0ubuntu8
1.1.1-0ubuntu9
1.1.4-0ubuntu2
1.1.4-0ubuntu3
1.1.4-0ubuntu4
1.1.4-0ubuntu5
1.2.0-0ubuntu1
1.2.0-0ubuntu2
1.2.0-0ubuntu3
1.2.1-0ubuntu1
1.2.1-0ubuntu2
1.2.1-0ubuntu3
1.2.1-0ubuntu4
1.2.1-0ubuntu5
1.2.1-0ubuntu7
1.2.1-0ubuntu8
1.2.1-0ubuntu9
1.2.1-0ubuntu10
1.2.2-0ubuntu1
1.2.2-0ubuntu2
1.2.2-0ubuntu3
1.2.2-0ubuntu4
1.2.2-0ubuntu5
1.2.2-0ubuntu6
1.2.2-0ubuntu7
1.2.2-0ubuntu8
1.2.2-0ubuntu9
1.2.2-0ubuntu10
1.2.2-0ubuntu11
1.2.2-0ubuntu12
1.2.2-0ubuntu13
1.2.2-0ubuntu13.1
1.2.2-0ubuntu13.1.1
1.2.2-0ubuntu13.1.2
1.2.2-0ubuntu13.1.4
1.2.2-0ubuntu13.1.5
1.2.2-0ubuntu13.1.6
1.2.2-0ubuntu13.1.7
1.2.2-0ubuntu13.1.8
1.2.2-0ubuntu13.1.9
1.2.2-0ubuntu13.1.10
1.2.2-0ubuntu13.1.12
1.2.2-0ubuntu13.1.14
1.2.2-0ubuntu13.1.16
1.2.2-0ubuntu13.1.17
1.2.2-0ubuntu13.1.20
1.2.2-0ubuntu13.1.21
1.2.2-0ubuntu13.1.22
1.2.2-0ubuntu13.1.23
1.2.2-0ubuntu13.1.25
1.2.2-0ubuntu13.1.26
1.2.2-0ubuntu13.1.27
1.2.2-0ubuntu13.1.28
1.2.2-0ubuntu13.1.28+esm1

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro with Legacy support add-on: https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_name": "libvirt-bin",
            "binary_version": "1.2.2-0ubuntu13.1.28+esm2"
        },
        {
            "binary_name": "libvirt0",
            "binary_version": "1.2.2-0ubuntu13.1.28+esm2"
        }
    ]
}

Database specific

cves_map
{
    "cves": [
        {
            "id": "CVE-2024-1441",
            "severity": [
                {
                    "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
                    "type": "CVSS_V3"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2024-2494",
            "severity": [
                {
                    "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                    "type": "CVSS_V3"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2024-2496",
            "severity": [
                {
                    "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H",
                    "type": "CVSS_V3"
                },
                {
                    "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
                    "type": "CVSS_V3"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2025-13193",
            "severity": [
                {
                    "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
                    "type": "CVSS_V3"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2026-61478",
            "severity": [
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2026-63623",
            "severity": [
                {
                    "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
                    "type": "CVSS_V3"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        }
    ],
    "ecosystem": "Ubuntu:Pro:14.04:LTS"
}
source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8652-1.json"
Ubuntu:Pro:16.04:LTS
libvirt

Package

Name
libvirt
Purl
pkg:deb/ubuntu/libvirt?arch=source&distro=esm-infra-legacy%2Fxenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.3.1-1ubuntu10.31+esm1

Affected versions

1.*
1.2.16-2ubuntu11
1.2.16-2ubuntu12
1.2.16-2ubuntu13
1.2.16-2ubuntu14
1.2.21-2ubuntu1
1.2.21-2ubuntu3
1.2.21-2ubuntu4
1.2.21-2ubuntu5
1.2.21-2ubuntu7
1.2.21-2ubuntu8
1.2.21-2ubuntu9
1.2.21-2ubuntu10
1.3.1-1ubuntu1
1.3.1-1ubuntu2
1.3.1-1ubuntu3
1.3.1-1ubuntu4
1.3.1-1ubuntu6
1.3.1-1ubuntu9
1.3.1-1ubuntu10
1.3.1-1ubuntu10.1
1.3.1-1ubuntu10.2
1.3.1-1ubuntu10.3
1.3.1-1ubuntu10.5
1.3.1-1ubuntu10.6
1.3.1-1ubuntu10.7
1.3.1-1ubuntu10.8
1.3.1-1ubuntu10.10
1.3.1-1ubuntu10.11
1.3.1-1ubuntu10.12
1.3.1-1ubuntu10.13
1.3.1-1ubuntu10.14
1.3.1-1ubuntu10.15
1.3.1-1ubuntu10.17
1.3.1-1ubuntu10.18
1.3.1-1ubuntu10.19
1.3.1-1ubuntu10.21
1.3.1-1ubuntu10.22
1.3.1-1ubuntu10.23
1.3.1-1ubuntu10.24
1.3.1-1ubuntu10.25
1.3.1-1ubuntu10.26
1.3.1-1ubuntu10.27
1.3.1-1ubuntu10.29
1.3.1-1ubuntu10.30
1.3.1-1ubuntu10.31

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro with Legacy support add-on: https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_name": "libvirt-bin",
            "binary_version": "1.3.1-1ubuntu10.31+esm1"
        },
        {
            "binary_name": "libvirt0",
            "binary_version": "1.3.1-1ubuntu10.31+esm1"
        }
    ]
}

Database specific

cves_map
{
    "cves": [
        {
            "id": "CVE-2021-4147",
            "severity": [
                {
                    "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H",
                    "type": "CVSS_V3"
                },
                {
                    "score": "low",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2024-1441",
            "severity": [
                {
                    "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
                    "type": "CVSS_V3"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2024-2494",
            "severity": [
                {
                    "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                    "type": "CVSS_V3"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2024-2496",
            "severity": [
                {
                    "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H",
                    "type": "CVSS_V3"
                },
                {
                    "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
                    "type": "CVSS_V3"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2025-13193",
            "severity": [
                {
                    "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
                    "type": "CVSS_V3"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2026-61477",
            "severity": [
                {
                    "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N",
                    "type": "CVSS_V3"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2026-61478",
            "severity": [
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2026-63623",
            "severity": [
                {
                    "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
                    "type": "CVSS_V3"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        }
    ],
    "ecosystem": "Ubuntu:Pro:16.04:LTS"
}
source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8652-1.json"
Ubuntu:Pro:18.04:LTS
libvirt

Package

Name
libvirt
Purl
pkg:deb/ubuntu/libvirt?arch=source&distro=esm-infra%2Fbionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4.0.0-1ubuntu8.21+esm1

Affected versions

3.*
3.6.0-1ubuntu5
3.6.0-1ubuntu6
4.*
4.0.0-1ubuntu1
4.0.0-1ubuntu2
4.0.0-1ubuntu3
4.0.0-1ubuntu4
4.0.0-1ubuntu5
4.0.0-1ubuntu6
4.0.0-1ubuntu7
4.0.0-1ubuntu8
4.0.0-1ubuntu8.1
4.0.0-1ubuntu8.2
4.0.0-1ubuntu8.3
4.0.0-1ubuntu8.4
4.0.0-1ubuntu8.5
4.0.0-1ubuntu8.6
4.0.0-1ubuntu8.7
4.0.0-1ubuntu8.8
4.0.0-1ubuntu8.9
4.0.0-1ubuntu8.10
4.0.0-1ubuntu8.11
4.0.0-1ubuntu8.12
4.0.0-1ubuntu8.13
4.0.0-1ubuntu8.14
4.0.0-1ubuntu8.15
4.0.0-1ubuntu8.16
4.0.0-1ubuntu8.17
4.0.0-1ubuntu8.19
4.0.0-1ubuntu8.20
4.0.0-1ubuntu8.21

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_name": "libnss-libvirt",
            "binary_version": "4.0.0-1ubuntu8.21+esm1"
        },
        {
            "binary_name": "libvirt-bin",
            "binary_version": "4.0.0-1ubuntu8.21+esm1"
        },
        {
            "binary_name": "libvirt-clients",
            "binary_version": "4.0.0-1ubuntu8.21+esm1"
        },
        {
            "binary_name": "libvirt-daemon",
            "binary_version": "4.0.0-1ubuntu8.21+esm1"
        },
        {
            "binary_name": "libvirt-daemon-driver-storage-gluster",
            "binary_version": "4.0.0-1ubuntu8.21+esm1"
        },
        {
            "binary_name": "libvirt-daemon-driver-storage-rbd",
            "binary_version": "4.0.0-1ubuntu8.21+esm1"
        },
        {
            "binary_name": "libvirt-daemon-driver-storage-sheepdog",
            "binary_version": "4.0.0-1ubuntu8.21+esm1"
        },
        {
            "binary_name": "libvirt-daemon-driver-storage-zfs",
            "binary_version": "4.0.0-1ubuntu8.21+esm1"
        },
        {
            "binary_name": "libvirt-daemon-system",
            "binary_version": "4.0.0-1ubuntu8.21+esm1"
        },
        {
            "binary_name": "libvirt-sanlock",
            "binary_version": "4.0.0-1ubuntu8.21+esm1"
        },
        {
            "binary_name": "libvirt-wireshark",
            "binary_version": "4.0.0-1ubuntu8.21+esm1"
        },
        {
            "binary_name": "libvirt0",
            "binary_version": "4.0.0-1ubuntu8.21+esm1"
        }
    ]
}

Database specific

cves_map
{
    "cves": [
        {
            "id": "CVE-2024-1441",
            "severity": [
                {
                    "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
                    "type": "CVSS_V3"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2024-2494",
            "severity": [
                {
                    "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                    "type": "CVSS_V3"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2024-2496",
            "severity": [
                {
                    "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H",
                    "type": "CVSS_V3"
                },
                {
                    "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
                    "type": "CVSS_V3"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2025-13193",
            "severity": [
                {
                    "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
                    "type": "CVSS_V3"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2026-61477",
            "severity": [
                {
                    "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N",
                    "type": "CVSS_V3"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2026-61478",
            "severity": [
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2026-63623",
            "severity": [
                {
                    "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
                    "type": "CVSS_V3"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        }
    ],
    "ecosystem": "Ubuntu:Pro:18.04:LTS"
}
source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8652-1.json"
Ubuntu:Pro:20.04:LTS
libvirt

Package

Name
libvirt
Purl
pkg:deb/ubuntu/libvirt?arch=source&distro=esm-infra%2Ffocal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
6.0.0-0ubuntu8.20+esm1

Affected versions

5.*
5.4.0-0ubuntu5
6.*
6.0.0-0ubuntu1
6.0.0-0ubuntu2
6.0.0-0ubuntu3
6.0.0-0ubuntu4
6.0.0-0ubuntu5
6.0.0-0ubuntu6
6.0.0-0ubuntu7
6.0.0-0ubuntu8
6.0.0-0ubuntu8.1
6.0.0-0ubuntu8.2
6.0.0-0ubuntu8.3
6.0.0-0ubuntu8.4
6.0.0-0ubuntu8.5
6.0.0-0ubuntu8.7
6.0.0-0ubuntu8.8
6.0.0-0ubuntu8.9
6.0.0-0ubuntu8.10
6.0.0-0ubuntu8.11
6.0.0-0ubuntu8.12
6.0.0-0ubuntu8.13
6.0.0-0ubuntu8.14
6.0.0-0ubuntu8.15
6.0.0-0ubuntu8.16
6.0.0-0ubuntu8.19
6.0.0-0ubuntu8.20

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_name": "libnss-libvirt",
            "binary_version": "6.0.0-0ubuntu8.20+esm1"
        },
        {
            "binary_name": "libvirt-clients",
            "binary_version": "6.0.0-0ubuntu8.20+esm1"
        },
        {
            "binary_name": "libvirt-daemon",
            "binary_version": "6.0.0-0ubuntu8.20+esm1"
        },
        {
            "binary_name": "libvirt-daemon-driver-lxc",
            "binary_version": "6.0.0-0ubuntu8.20+esm1"
        },
        {
            "binary_name": "libvirt-daemon-driver-qemu",
            "binary_version": "6.0.0-0ubuntu8.20+esm1"
        },
        {
            "binary_name": "libvirt-daemon-driver-storage-gluster",
            "binary_version": "6.0.0-0ubuntu8.20+esm1"
        },
        {
            "binary_name": "libvirt-daemon-driver-storage-rbd",
            "binary_version": "6.0.0-0ubuntu8.20+esm1"
        },
        {
            "binary_name": "libvirt-daemon-driver-storage-zfs",
            "binary_version": "6.0.0-0ubuntu8.20+esm1"
        },
        {
            "binary_name": "libvirt-daemon-driver-vbox",
            "binary_version": "6.0.0-0ubuntu8.20+esm1"
        },
        {
            "binary_name": "libvirt-daemon-driver-xen",
            "binary_version": "6.0.0-0ubuntu8.20+esm1"
        },
        {
            "binary_name": "libvirt-daemon-system",
            "binary_version": "6.0.0-0ubuntu8.20+esm1"
        },
        {
            "binary_name": "libvirt-daemon-system-systemd",
            "binary_version": "6.0.0-0ubuntu8.20+esm1"
        },
        {
            "binary_name": "libvirt-daemon-system-sysv",
            "binary_version": "6.0.0-0ubuntu8.20+esm1"
        },
        {
            "binary_name": "libvirt-sanlock",
            "binary_version": "6.0.0-0ubuntu8.20+esm1"
        },
        {
            "binary_name": "libvirt-wireshark",
            "binary_version": "6.0.0-0ubuntu8.20+esm1"
        },
        {
            "binary_name": "libvirt0",
            "binary_version": "6.0.0-0ubuntu8.20+esm1"
        }
    ]
}

Database specific

cves_map
{
    "cves": [
        {
            "id": "CVE-2025-13193",
            "severity": [
                {
                    "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
                    "type": "CVSS_V3"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2026-61477",
            "severity": [
                {
                    "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N",
                    "type": "CVSS_V3"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2026-61478",
            "severity": [
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2026-63622",
            "severity": [
                {
                    "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "type": "CVSS_V3"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2026-63623",
            "severity": [
                {
                    "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
                    "type": "CVSS_V3"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        }
    ],
    "ecosystem": "Ubuntu:Pro:20.04:LTS"
}
source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8652-1.json"