<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T02:13:26.088575+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-350827</id>
    <title>EUVD-2026-350827</title>
    <updated>2026-10-04T02:13:26.268946+00:00</updated>
    <content>EUVD-2026-350827</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-350827"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-63623</id>
    <title>fkie_cve-2026-63623</title>
    <updated>2026-10-04T02:13:26.268997+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in libvirt. During storage volume clone or convert operations, newly created volume images were temporarily world-readable. This was caused by the `qemu-img` utility running with overly permissive file creation settings, allowing any local user to read the full guest disk contents. This vulnerability could lead to sensitive information disclosure from guest virtual machines.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-63623"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-m7jx-933m-5cqr</id>
    <title>GHSA-m7jx-933m-5cqr</title>
    <updated>2026-10-04T02:13:26.269032+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in libvirt. During storage volume clone or convert operations, newly created volume images were temporarily world-readable. This was caused by the `qemu-img` utility running with overly permissive file creation settings, allowing any local user to read the full guest disk contents. This vulnerability could lead to sensitive information disclosure from guest virtual machines.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-m7jx-933m-5cqr"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-63623</id>
    <title>msrc_CVE-2026-63623 — Libvirt: information disclosure via world-readable storage volume images during clone/convert</title>
    <updated>2026-10-04T02:13:26.269051+00:00</updated>
    <content>msrc_CVE-2026-63623</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-63623"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-3831</id>
    <title>OESA-2026-3831 — libvirt security update</title>
    <updated>2026-10-04T02:13:26.269069+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP1: libvirt</p>
<p>Libvirt is a C toolkit to interact with the virtualization capabilities of recent versions of Linux (and other OSes). The main package includes the libvirtd server exporting the virtualization support.

Security Fix(es):</p>
<p>A flaw was found in libvirt. During storage volume clone or convert operations, newly created volume images were temporarily world-readable. This was caused by the `qemu-img` utility running with overly permissive file creation settings, allowing any local user to read the full guest disk contents. This vulnerability could lead to sensitive information disclosure from guest virtual machines.(CVE-2026-63623)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-3831"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11455-1</id>
    <title>openSUSE-SU-2026:11455-1 — libvirt-12.6.0-1.1 on GA media</title>
    <updated>2026-10-04T02:13:26.269096+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libvirt-12.6.0-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11455-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:23445-1</id>
    <title>SUSE-SU-2026:23445-1 — Security update for libvirt</title>
    <updated>2026-10-04T02:13:26.269112+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for libvirt</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:23445-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-63623</id>
    <title>UBUNTU-CVE-2026-63623</title>
    <updated>2026-10-04T02:13:26.269129+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: libvirt, Ubuntu:Pro:16.04:LTS: libvirt, Ubuntu:Pro:18.04:LTS: libvirt, Ubuntu:Pro:20.04:LTS: libvirt, Ubuntu:22.04:LTS: libvirt, Ubuntu:24.04:LTS: libvirt, Ubuntu:26.04:LTS: libvirt, Ubuntu:26.04:LTS: libvirt-hwe</p>
<p>A flaw was found in libvirt. During storage volume clone or convert operations, newly created volume images were temporarily world-readable. This was caused by the `qemu-img` utility running with overly permissive file creation settings, allowing any local user to read the full guest disk contents. This vulnerability could lead to sensitive information disclosure from guest virtual machines.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-63623"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2724</id>
    <title>WID-SEC-W-2026-2724 — libvirt: Mehrere Schwachstellen ermöglichen</title>
    <updated>2026-10-04T02:13:26.269160+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann mehrere Schwachstellen in libvirt ausnutzen, um Administratorrechte zu erlangen und vertrauliche Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2724"/>
  </entry>
</feed>
