Skip to content
Ubuntu 26.04 LTS libvirt Security Vulnerabilities USN-8833

Ubuntu 26.04 LTS libvirt Security Vulnerabilities USN-8833

Linuxsecurity •LinuxSecurity Advisories • September 28, 2026

CISA confirms exploitation of a Linux firewall flaw. Check if your systems need the fix. ×

Several security issues were fixed in libvirt. Software Description: - libvirt-hwe: Libvirt virtualization toolkit Details: It was discovered that libvirt did not properly validate newline characters in DNS TXT record values and SRV record attributes in its virtual network driver. A local attacker with permission to define virtual networks could possibly use this issue to inject arbitrary dnsmasq configuration directives, leading to arbitrary command execution as root. (CVE-2026-61477) It was discovered that libvirt did not properly handle errors during XML context parsing. An attacker could possibly use this issue to cause libvirt to crash, resulting in a denial of service. (CVE-2026-61478) He Wei discovered that libvirt had a symlink-following vulnerability in the file ownership change function used for virtual TPM state directories. A local attacker running as the swtpm user could possibly use this issue to cause libvirt to change the ownership of an arbitrary file, leading... Read the Full Advisory

Several security issues were fixed in libvirt.

Software Description:

- libvirt-hwe: Libvirt virtualization toolkit

It was discovered that libvirt did not properly validate newline characters

in DNS TXT record values and SRV record attributes in its virtual network

driver. A local attacker with permission to define virtual networks could

possibly use this issue to inject arbitrary dnsmasq configuration

directives, leading to arbitrary command execution as root.

It was discovered that libvirt did not properly handle errors during XML

context parsing. An attacker could possibly use this issue to cause libvirt

to crash, resulting in a denial of service. (CVE-2026-61478)

He Wei discovered that libvirt had a symlink-following vulnerability in the

file ownership change function used for virtual TPM state directories. A

local attacker running as the swtpm user could possibly use this issue to

cause libvirt to change the ownership of an arbitrary file, leading...

The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS libvirt-daemon-hwe 12.0.0-1ubuntu5.5 libvirt-daemon-system-hwe 12.0.0-1ubuntu5.5 libvirt0-hwe 12.0.0-1ubuntu5.5 After a standard system update you need to reboot your computer to make all the necessary changes.

CVE-2026-18917, CVE-2026-61477, CVE-2026-61478, CVE-2026-63622,

CVE-2026-63623, CVE-2026-77159

Ubuntu Security Notice USN-8833-1

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Linux Security - Your source for Top Linux News, Advisories, HOWTOs and Feature Releases