openSUSE-SU-2026:21738-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21738-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/openSUSE-SU-2026:21738-1
Upstream
CVE (5)
  • CVE-2026-18917
  • CVE-2026-61477
  • CVE-2026-63622
  • CVE-2026-63623
  • CVE-2026-77159
Related
Published
2026-09-02T09:43:39Z
Modified
2026-09-09T18:23:24Z
Summary
Security update for libvirt
Details

This update for libvirt fixes the following issues:

  • CVE-2026-18917: integer overflow in NodeGetFreePages RPC handler leads to heap buffer overflow and allows for possible local privilege escalation (bsc#1275863).
  • CVE-2026-61477: newline injection in network XML DNS TXT/SRV fields allows for dnsmasq configuration directive injection and can lead to arbitrary code execution as root (bsc#1274576).
  • CVE-2026-63622: symlink-following in virFileChownFiles() allows swtpm user to trick the root-level libvirt daemon into changing the ownership of an arbitrary file and can lead to privilege escalation (bsc#1275264).
  • CVE-2026-63623: newly created volume images are temporarily world-readable during clone/convert operations, which can lead to sensitive information disclosure (bsc#1275265).
  • CVE-2026-77159: root chown() on swtpm logfile follows symlinks and allows for root-owned file ownership changes, which can lead to privilege escalation (bsc#1274946).
References

Affected packages

openSUSE:Leap 16.0 / libvirt

Package

Name
libvirt
Purl
pkg:rpm/opensuse/libvirt&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
11.4.0-160000.5.1

Ecosystem specific

{
    "binaries": [
        {
            "libvirt": "11.4.0-160000.5.1",
            "libvirt-client": "11.4.0-160000.5.1",
            "libvirt-client-qemu": "11.4.0-160000.5.1",
            "libvirt-daemon": "11.4.0-160000.5.1",
            "libvirt-daemon-common": "11.4.0-160000.5.1",
            "libvirt-daemon-config-network": "11.4.0-160000.5.1",
            "libvirt-daemon-config-nwfilter": "11.4.0-160000.5.1",
            "libvirt-daemon-driver-network": "11.4.0-160000.5.1",
            "libvirt-daemon-driver-nodedev": "11.4.0-160000.5.1",
            "libvirt-daemon-driver-nwfilter": "11.4.0-160000.5.1",
            "libvirt-daemon-driver-qemu": "11.4.0-160000.5.1",
            "libvirt-daemon-driver-secret": "11.4.0-160000.5.1",
            "libvirt-daemon-driver-storage": "11.4.0-160000.5.1",
            "libvirt-daemon-driver-storage-core": "11.4.0-160000.5.1",
            "libvirt-daemon-driver-storage-disk": "11.4.0-160000.5.1",
            "libvirt-daemon-driver-storage-iscsi": "11.4.0-160000.5.1",
            "libvirt-daemon-driver-storage-iscsi-direct": "11.4.0-160000.5.1",
            "libvirt-daemon-driver-storage-logical": "11.4.0-160000.5.1",
            "libvirt-daemon-driver-storage-mpath": "11.4.0-160000.5.1",
            "libvirt-daemon-driver-storage-scsi": "11.4.0-160000.5.1",
            "libvirt-daemon-hooks": "11.4.0-160000.5.1",
            "libvirt-daemon-lock": "11.4.0-160000.5.1",
            "libvirt-daemon-log": "11.4.0-160000.5.1",
            "libvirt-daemon-plugin-lockd": "11.4.0-160000.5.1",
            "libvirt-daemon-proxy": "11.4.0-160000.5.1",
            "libvirt-daemon-qemu": "11.4.0-160000.5.1",
            "libvirt-devel": "11.4.0-160000.5.1",
            "libvirt-doc": "11.4.0-160000.5.1",
            "libvirt-libs": "11.4.0-160000.5.1",
            "libvirt-nss": "11.4.0-160000.5.1",
            "libvirt-ssh-proxy": "11.4.0-160000.5.1",
            "wireshark-plugin-libvirt": "11.4.0-160000.5.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21738-1.json"