Back Linuxsecurity Ubuntu 26.04 LTS libvirt Security Vulnerabilities USN-8833
CISA confirms exploitation of a Linux firewall flaw. Check if your systems need the fix. ×
Several security issues were fixed in libvirt. Software Description: - libvirt-hwe: Libvirt virtualization toolkit Details: It was discovered that libvirt did not properly validate newline characters in DNS TXT record values and SRV record attributes in its virtual network driver. A local attacker with permission to define virtual networks could possibly use this issue to inject arbitrary dnsmasq configuration directives, leading to arbitrary command execution as root. (CVE-2026-61477) It was discovered that libvirt did not properly handle errors during XML context parsing. An attacker could possibly use this issue to cause libvirt to crash, resulting in a denial of service. (CVE-2026-61478) He Wei discovered that libvirt had a symlink-following vulnerability in the file ownership change function used for virtual TPM state directories. A local attacker running as the swtpm user could possibly use this issue to cause libvirt to change the ownership of an arbitrary file, leading... Read the Full Advisory
Several security issues were fixed in libvirt.
Software Description:
- libvirt-hwe: Libvirt virtualization toolkit
It was discovered that libvirt did not properly validate newline characters
in DNS TXT record values and SRV record attributes in its virtual network
driver. A local attacker with permission to define virtual networks could
possibly use this issue to inject arbitrary dnsmasq configuration
directives, leading to arbitrary command execution as root.
It was discovered that libvirt did not properly handle errors during XML
context parsing. An attacker could possibly use this issue to cause libvirt
to crash, resulting in a denial of service. (CVE-2026-61478)
He Wei discovered that libvirt had a symlink-following vulnerability in the
file ownership change function used for virtual TPM state directories. A
local attacker running as the swtpm user could possibly use this issue to
cause libvirt to change the ownership of an arbitrary file, leading...
The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS libvirt-daemon-hwe 12.0.0-1ubuntu5.5 libvirt-daemon-system-hwe 12.0.0-1ubuntu5.5 libvirt0-hwe 12.0.0-1ubuntu5.5 After a standard system update you need to reboot your computer to make all the necessary changes.
CVE-2026-18917, CVE-2026-61477, CVE-2026-61478, CVE-2026-63622,
CVE-2026-63623, CVE-2026-77159
Ubuntu Security Notice USN-8833-1
Get the latest News and Insights
Get the latest Linux and open source security news straight to your inbox.
Linux Security - Your source for Top Linux News, Advisories, HOWTOs and Feature Releases
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
