It was discovered that libvirt incorrectly handled guest reboots in the libxl driver. An attacker in a guest could possibly use this issue to cause the libvirt daemon to crash, resulting in a denial of service. This issue only affected Ubuntu 16.04 LTS. (CVE-2021-4147)
Alexander Kuznetsov discovered that libvirt incorrectly handled listing network interfaces. An attacker could possibly use this issue to cause the libvirt daemon to crash, resulting in a denial of service. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 18.04 LTS. (CVE-2024-1441)
It was discovered that libvirt incorrectly handled certain values in its RPC library. An attacker could possibly use this issue to cause the libvirt daemon to crash, resulting in a denial of service. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 18.04 LTS. (CVE-2024-2494)
It was discovered that libvirt incorrectly handled listing network interfaces under certain circumstances. An attacker could possibly use this issue to cause the libvirt daemon to crash, resulting in a denial of service. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 18.04 LTS. (CVE-2024-2496)
It was discovered that libvirt incorrectly set permissions on external inactive snapshots, making them world-readable. A local attacker could possibly use this issue to obtain sensitive information. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. (CVE-2025-13193)
It was discovered that libvirt incorrectly handled certain characters in virtual network definitions. An authenticated user could possibly use this issue to inject arbitrary configuration directives and execute arbitrary code as root. This issue did not affect Ubuntu 14.04 LTS. (CVE-2026-61477)
It was discovered that libvirt incorrectly handled certain XML input. An attacker could possibly use this issue to cause the libvirt daemon to crash, resulting in a denial of service. (CVE-2026-61478)
He Wei discovered that libvirt incorrectly followed symbolic links when changing file ownership. A local attacker could possibly use this issue to escalate privileges. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-63622)
It was discovered that libvirt incorrectly set permissions on images during storage volume clone and convert operations, making them temporarily world-readable. A local attacker could possibly use this issue to obtain sensitive information. (CVE-2026-63623)
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "libnss-libvirt",
"binary_version": "8.0.0-1ubuntu7.19"
},
{
"binary_name": "libvirt-clients",
"binary_version": "8.0.0-1ubuntu7.19"
},
{
"binary_name": "libvirt-daemon",
"binary_version": "8.0.0-1ubuntu7.19"
},
{
"binary_name": "libvirt-daemon-config-network",
"binary_version": "8.0.0-1ubuntu7.19"
},
{
"binary_name": "libvirt-daemon-config-nwfilter",
"binary_version": "8.0.0-1ubuntu7.19"
},
{
"binary_name": "libvirt-daemon-driver-lxc",
"binary_version": "8.0.0-1ubuntu7.19"
},
{
"binary_name": "libvirt-daemon-driver-qemu",
"binary_version": "8.0.0-1ubuntu7.19"
},
{
"binary_name": "libvirt-daemon-driver-storage-gluster",
"binary_version": "8.0.0-1ubuntu7.19"
},
{
"binary_name": "libvirt-daemon-driver-storage-iscsi-direct",
"binary_version": "8.0.0-1ubuntu7.19"
},
{
"binary_name": "libvirt-daemon-driver-storage-rbd",
"binary_version": "8.0.0-1ubuntu7.19"
},
{
"binary_name": "libvirt-daemon-driver-storage-zfs",
"binary_version": "8.0.0-1ubuntu7.19"
},
{
"binary_name": "libvirt-daemon-driver-vbox",
"binary_version": "8.0.0-1ubuntu7.19"
},
{
"binary_name": "libvirt-daemon-driver-xen",
"binary_version": "8.0.0-1ubuntu7.19"
},
{
"binary_name": "libvirt-daemon-system",
"binary_version": "8.0.0-1ubuntu7.19"
},
{
"binary_name": "libvirt-daemon-system-systemd",
"binary_version": "8.0.0-1ubuntu7.19"
},
{
"binary_name": "libvirt-daemon-system-sysv",
"binary_version": "8.0.0-1ubuntu7.19"
},
{
"binary_name": "libvirt-login-shell",
"binary_version": "8.0.0-1ubuntu7.19"
},
{
"binary_name": "libvirt-sanlock",
"binary_version": "8.0.0-1ubuntu7.19"
},
{
"binary_name": "libvirt-wireshark",
"binary_version": "8.0.0-1ubuntu7.19"
},
{
"binary_name": "libvirt0",
"binary_version": "8.0.0-1ubuntu7.19"
}
]
}{
"cves": [
{
"id": "CVE-2026-61477",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2026-61478",
"severity": [
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2026-63622",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2026-63623",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
}
],
"ecosystem": "Ubuntu:22.04:LTS"
}
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8652-1.json"
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "libnss-libvirt",
"binary_version": "10.0.0-2ubuntu8.16"
},
{
"binary_name": "libvirt-clients",
"binary_version": "10.0.0-2ubuntu8.16"
},
{
"binary_name": "libvirt-clients-qemu",
"binary_version": "10.0.0-2ubuntu8.16"
},
{
"binary_name": "libvirt-daemon",
"binary_version": "10.0.0-2ubuntu8.16"
},
{
"binary_name": "libvirt-daemon-config-network",
"binary_version": "10.0.0-2ubuntu8.16"
},
{
"binary_name": "libvirt-daemon-config-nwfilter",
"binary_version": "10.0.0-2ubuntu8.16"
},
{
"binary_name": "libvirt-daemon-driver-lxc",
"binary_version": "10.0.0-2ubuntu8.16"
},
{
"binary_name": "libvirt-daemon-driver-qemu",
"binary_version": "10.0.0-2ubuntu8.16"
},
{
"binary_name": "libvirt-daemon-driver-storage-gluster",
"binary_version": "10.0.0-2ubuntu8.16"
},
{
"binary_name": "libvirt-daemon-driver-storage-iscsi-direct",
"binary_version": "10.0.0-2ubuntu8.16"
},
{
"binary_name": "libvirt-daemon-driver-storage-rbd",
"binary_version": "10.0.0-2ubuntu8.16"
},
{
"binary_name": "libvirt-daemon-driver-storage-zfs",
"binary_version": "10.0.0-2ubuntu8.16"
},
{
"binary_name": "libvirt-daemon-driver-vbox",
"binary_version": "10.0.0-2ubuntu8.16"
},
{
"binary_name": "libvirt-daemon-driver-xen",
"binary_version": "10.0.0-2ubuntu8.16"
},
{
"binary_name": "libvirt-daemon-system",
"binary_version": "10.0.0-2ubuntu8.16"
},
{
"binary_name": "libvirt-daemon-system-systemd",
"binary_version": "10.0.0-2ubuntu8.16"
},
{
"binary_name": "libvirt-daemon-system-sysv",
"binary_version": "10.0.0-2ubuntu8.16"
},
{
"binary_name": "libvirt-l10n",
"binary_version": "10.0.0-2ubuntu8.16"
},
{
"binary_name": "libvirt-login-shell",
"binary_version": "10.0.0-2ubuntu8.16"
},
{
"binary_name": "libvirt-sanlock",
"binary_version": "10.0.0-2ubuntu8.16"
},
{
"binary_name": "libvirt-wireshark",
"binary_version": "10.0.0-2ubuntu8.16"
},
{
"binary_name": "libvirt0",
"binary_version": "10.0.0-2ubuntu8.16"
}
]
}{
"cves": [
{
"id": "CVE-2026-61477",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2026-61478",
"severity": [
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2026-63622",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2026-63623",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
}
],
"ecosystem": "Ubuntu:24.04:LTS"
}
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8652-1.json"
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "libnss-libvirt",
"binary_version": "12.0.0-1ubuntu5.3"
},
{
"binary_name": "libvirt-clients",
"binary_version": "12.0.0-1ubuntu5.3"
},
{
"binary_name": "libvirt-clients-qemu",
"binary_version": "12.0.0-1ubuntu5.3"
},
{
"binary_name": "libvirt-common",
"binary_version": "12.0.0-1ubuntu5.3"
},
{
"binary_name": "libvirt-daemon",
"binary_version": "12.0.0-1ubuntu5.3"
},
{
"binary_name": "libvirt-daemon-common",
"binary_version": "12.0.0-1ubuntu5.3"
},
{
"binary_name": "libvirt-daemon-config-network",
"binary_version": "12.0.0-1ubuntu5.3"
},
{
"binary_name": "libvirt-daemon-config-nwfilter",
"binary_version": "12.0.0-1ubuntu5.3"
},
{
"binary_name": "libvirt-daemon-driver-interface",
"binary_version": "12.0.0-1ubuntu5.3"
},
{
"binary_name": "libvirt-daemon-driver-lxc",
"binary_version": "12.0.0-1ubuntu5.3"
},
{
"binary_name": "libvirt-daemon-driver-network",
"binary_version": "12.0.0-1ubuntu5.3"
},
{
"binary_name": "libvirt-daemon-driver-nodedev",
"binary_version": "12.0.0-1ubuntu5.3"
},
{
"binary_name": "libvirt-daemon-driver-nwfilter",
"binary_version": "12.0.0-1ubuntu5.3"
},
{
"binary_name": "libvirt-daemon-driver-qemu",
"binary_version": "12.0.0-1ubuntu5.3"
},
{
"binary_name": "libvirt-daemon-driver-secret",
"binary_version": "12.0.0-1ubuntu5.3"
},
{
"binary_name": "libvirt-daemon-driver-storage",
"binary_version": "12.0.0-1ubuntu5.3"
},
{
"binary_name": "libvirt-daemon-driver-storage-disk",
"binary_version": "12.0.0-1ubuntu5.3"
},
{
"binary_name": "libvirt-daemon-driver-storage-gluster",
"binary_version": "12.0.0-1ubuntu5.3"
},
{
"binary_name": "libvirt-daemon-driver-storage-iscsi",
"binary_version": "12.0.0-1ubuntu5.3"
},
{
"binary_name": "libvirt-daemon-driver-storage-iscsi-direct",
"binary_version": "12.0.0-1ubuntu5.3"
},
{
"binary_name": "libvirt-daemon-driver-storage-logical",
"binary_version": "12.0.0-1ubuntu5.3"
},
{
"binary_name": "libvirt-daemon-driver-storage-mpath",
"binary_version": "12.0.0-1ubuntu5.3"
},
{
"binary_name": "libvirt-daemon-driver-storage-rbd",
"binary_version": "12.0.0-1ubuntu5.3"
},
{
"binary_name": "libvirt-daemon-driver-storage-scsi",
"binary_version": "12.0.0-1ubuntu5.3"
},
{
"binary_name": "libvirt-daemon-driver-storage-zfs",
"binary_version": "12.0.0-1ubuntu5.3"
},
{
"binary_name": "libvirt-daemon-driver-vbox",
"binary_version": "12.0.0-1ubuntu5.3"
},
{
"binary_name": "libvirt-daemon-driver-xen",
"binary_version": "12.0.0-1ubuntu5.3"
},
{
"binary_name": "libvirt-daemon-lock",
"binary_version": "12.0.0-1ubuntu5.3"
},
{
"binary_name": "libvirt-daemon-log",
"binary_version": "12.0.0-1ubuntu5.3"
},
{
"binary_name": "libvirt-daemon-plugin-lockd",
"binary_version": "12.0.0-1ubuntu5.3"
},
{
"binary_name": "libvirt-daemon-plugin-sanlock",
"binary_version": "12.0.0-1ubuntu5.3"
},
{
"binary_name": "libvirt-daemon-system",
"binary_version": "12.0.0-1ubuntu5.3"
},
{
"binary_name": "libvirt-daemon-system-systemd",
"binary_version": "12.0.0-1ubuntu5.3"
},
{
"binary_name": "libvirt-daemon-system-sysv",
"binary_version": "12.0.0-1ubuntu5.3"
},
{
"binary_name": "libvirt-l10n",
"binary_version": "12.0.0-1ubuntu5.3"
},
{
"binary_name": "libvirt-login-shell",
"binary_version": "12.0.0-1ubuntu5.3"
},
{
"binary_name": "libvirt-sanlock",
"binary_version": "12.0.0-1ubuntu5.3"
},
{
"binary_name": "libvirt-ssh-proxy",
"binary_version": "12.0.0-1ubuntu5.3"
},
{
"binary_name": "libvirt-wireshark",
"binary_version": "12.0.0-1ubuntu5.3"
},
{
"binary_name": "libvirt0",
"binary_version": "12.0.0-1ubuntu5.3"
}
]
}{
"cves": [
{
"id": "CVE-2026-61477",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2026-61478",
"severity": [
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2026-63622",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2026-63623",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
}
],
"ecosystem": "Ubuntu:26.04:LTS"
}
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8652-1.json"
{
"availability": "Available with Ubuntu Pro with Legacy support add-on: https://ubuntu.com/pro",
"binaries": [
{
"binary_name": "libvirt-bin",
"binary_version": "1.2.2-0ubuntu13.1.28+esm2"
},
{
"binary_name": "libvirt0",
"binary_version": "1.2.2-0ubuntu13.1.28+esm2"
}
]
}{
"cves": [
{
"id": "CVE-2024-1441",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2024-2494",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2024-2496",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
},
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2025-13193",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2026-61478",
"severity": [
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2026-63623",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
}
],
"ecosystem": "Ubuntu:Pro:14.04:LTS"
}
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8652-1.json"
{
"availability": "Available with Ubuntu Pro with Legacy support add-on: https://ubuntu.com/pro",
"binaries": [
{
"binary_name": "libvirt-bin",
"binary_version": "1.3.1-1ubuntu10.31+esm1"
},
{
"binary_name": "libvirt0",
"binary_version": "1.3.1-1ubuntu10.31+esm1"
}
]
}{
"cves": [
{
"id": "CVE-2021-4147",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H",
"type": "CVSS_V3"
},
{
"score": "low",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2024-1441",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2024-2494",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2024-2496",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
},
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2025-13193",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2026-61477",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2026-61478",
"severity": [
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2026-63623",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
}
],
"ecosystem": "Ubuntu:Pro:16.04:LTS"
}
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8652-1.json"
{
"availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
"binaries": [
{
"binary_name": "libnss-libvirt",
"binary_version": "4.0.0-1ubuntu8.21+esm1"
},
{
"binary_name": "libvirt-bin",
"binary_version": "4.0.0-1ubuntu8.21+esm1"
},
{
"binary_name": "libvirt-clients",
"binary_version": "4.0.0-1ubuntu8.21+esm1"
},
{
"binary_name": "libvirt-daemon",
"binary_version": "4.0.0-1ubuntu8.21+esm1"
},
{
"binary_name": "libvirt-daemon-driver-storage-gluster",
"binary_version": "4.0.0-1ubuntu8.21+esm1"
},
{
"binary_name": "libvirt-daemon-driver-storage-rbd",
"binary_version": "4.0.0-1ubuntu8.21+esm1"
},
{
"binary_name": "libvirt-daemon-driver-storage-sheepdog",
"binary_version": "4.0.0-1ubuntu8.21+esm1"
},
{
"binary_name": "libvirt-daemon-driver-storage-zfs",
"binary_version": "4.0.0-1ubuntu8.21+esm1"
},
{
"binary_name": "libvirt-daemon-system",
"binary_version": "4.0.0-1ubuntu8.21+esm1"
},
{
"binary_name": "libvirt-sanlock",
"binary_version": "4.0.0-1ubuntu8.21+esm1"
},
{
"binary_name": "libvirt-wireshark",
"binary_version": "4.0.0-1ubuntu8.21+esm1"
},
{
"binary_name": "libvirt0",
"binary_version": "4.0.0-1ubuntu8.21+esm1"
}
]
}{
"cves": [
{
"id": "CVE-2024-1441",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2024-2494",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2024-2496",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
},
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2025-13193",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2026-61477",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2026-61478",
"severity": [
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2026-63623",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
}
],
"ecosystem": "Ubuntu:Pro:18.04:LTS"
}
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8652-1.json"
{
"availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
"binaries": [
{
"binary_name": "libnss-libvirt",
"binary_version": "6.0.0-0ubuntu8.20+esm1"
},
{
"binary_name": "libvirt-clients",
"binary_version": "6.0.0-0ubuntu8.20+esm1"
},
{
"binary_name": "libvirt-daemon",
"binary_version": "6.0.0-0ubuntu8.20+esm1"
},
{
"binary_name": "libvirt-daemon-driver-lxc",
"binary_version": "6.0.0-0ubuntu8.20+esm1"
},
{
"binary_name": "libvirt-daemon-driver-qemu",
"binary_version": "6.0.0-0ubuntu8.20+esm1"
},
{
"binary_name": "libvirt-daemon-driver-storage-gluster",
"binary_version": "6.0.0-0ubuntu8.20+esm1"
},
{
"binary_name": "libvirt-daemon-driver-storage-rbd",
"binary_version": "6.0.0-0ubuntu8.20+esm1"
},
{
"binary_name": "libvirt-daemon-driver-storage-zfs",
"binary_version": "6.0.0-0ubuntu8.20+esm1"
},
{
"binary_name": "libvirt-daemon-driver-vbox",
"binary_version": "6.0.0-0ubuntu8.20+esm1"
},
{
"binary_name": "libvirt-daemon-driver-xen",
"binary_version": "6.0.0-0ubuntu8.20+esm1"
},
{
"binary_name": "libvirt-daemon-system",
"binary_version": "6.0.0-0ubuntu8.20+esm1"
},
{
"binary_name": "libvirt-daemon-system-systemd",
"binary_version": "6.0.0-0ubuntu8.20+esm1"
},
{
"binary_name": "libvirt-daemon-system-sysv",
"binary_version": "6.0.0-0ubuntu8.20+esm1"
},
{
"binary_name": "libvirt-sanlock",
"binary_version": "6.0.0-0ubuntu8.20+esm1"
},
{
"binary_name": "libvirt-wireshark",
"binary_version": "6.0.0-0ubuntu8.20+esm1"
},
{
"binary_name": "libvirt0",
"binary_version": "6.0.0-0ubuntu8.20+esm1"
}
]
}{
"cves": [
{
"id": "CVE-2025-13193",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2026-61477",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2026-61478",
"severity": [
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2026-63622",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2026-63623",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
}
],
"ecosystem": "Ubuntu:Pro:20.04:LTS"
}
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8652-1.json"