<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 13:34:15 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-350827</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-350827</link>
      <description>EUVD-2026-350827</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-350827</guid>
    </item>
    <item>
      <title>fkie_cve-2026-63623</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-63623</link>
      <description>&lt;p&gt;A flaw was found in libvirt. During storage volume clone or convert operations, newly created volume images were temporarily world-readable. This was caused by the `qemu-img` utility running with overly permissive file creation settings, allowing any local user to read the full guest disk contents. This vulnerability could lead to sensitive information disclosure from guest virtual machines.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in libvirt. During storage volume clone or convert operations, newly created volume images were temporarily world-readable. This was caused by the `qemu-img` utility running with overly permissive file creation settings, allowing any local user to read the full guest disk contents. This vulnerability could lead to sensitive information disclosure from guest virtual machines.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-63623</guid>
    </item>
    <item>
      <title>GHSA-m7jx-933m-5cqr</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-m7jx-933m-5cqr</link>
      <description>&lt;p&gt;A flaw was found in libvirt. During storage volume clone or convert operations, newly created volume images were temporarily world-readable. This was caused by the `qemu-img` utility running with overly permissive file creation settings, allowing any local user to read the full guest disk contents. This vulnerability could lead to sensitive information disclosure from guest virtual machines.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in libvirt. During storage volume clone or convert operations, newly created volume images were temporarily world-readable. This was caused by the `qemu-img` utility running with overly permissive file creation settings, allowing any local user to read the full guest disk contents. This vulnerability could lead to sensitive information disclosure from guest virtual machines.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-m7jx-933m-5cqr</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-63623 — Libvirt: information disclosure via world-readable storage volume images during clone/convert</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-63623</link>
      <description>msrc_CVE-2026-63623</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-63623</guid>
    </item>
    <item>
      <title>OESA-2026-3831 — libvirt security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-3831</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: libvirt&lt;/p&gt;
&lt;p&gt;Libvirt is a C toolkit to interact with the virtualization capabilities of recent versions of Linux (and other OSes). The main package includes the libvirtd server exporting the virtualization support.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A flaw was found in libvirt. During storage volume clone or convert operations, newly created volume images were temporarily world-readable. This was caused by the `qemu-img` utility running with overly permissive file creation settings, allowing any local user to read the full guest disk contents. This vulnerability could lead to sensitive information disclosure from guest virtual machines.(CVE-2026-63623)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: libvirt&lt;/p&gt;
&lt;p&gt;Libvirt is a C toolkit to interact with the virtualization capabilities of recent versions of Linux (and other OSes). The main package includes the libvirtd server exporting the virtualization support.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A flaw was found in libvirt. During storage volume clone or convert operations, newly created volume images were temporarily world-readable. This was caused by the `qemu-img` utility running with overly permissive file creation settings, allowing any local user to read the full guest disk contents. This vulnerability could lead to sensitive information disclosure from guest virtual machines.(CVE-2026-63623)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-3831</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11455-1 — libvirt-12.6.0-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11455-1</link>
      <description>&lt;p&gt;libvirt-12.6.0-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libvirt-12.6.0-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11455-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:23445-1 — Security update for libvirt</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:23445-1</link>
      <description>&lt;p&gt;Security update for libvirt&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for libvirt&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:23445-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-63623</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-63623</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: libvirt, Ubuntu:Pro:16.04:LTS: libvirt, Ubuntu:Pro:18.04:LTS: libvirt, Ubuntu:Pro:20.04:LTS: libvirt, Ubuntu:22.04:LTS: libvirt, Ubuntu:24.04:LTS: libvirt, Ubuntu:26.04:LTS: libvirt, Ubuntu:26.04:LTS: libvirt-hwe&lt;/p&gt;
&lt;p&gt;A flaw was found in libvirt. During storage volume clone or convert operations, newly created volume images were temporarily world-readable. This was caused by the `qemu-img` utility running with overly permissive file creation settings, allowing any local user to read the full guest disk contents. This vulnerability could lead to sensitive information disclosure from guest virtual machines.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: libvirt, Ubuntu:Pro:16.04:LTS: libvirt, Ubuntu:Pro:18.04:LTS: libvirt, Ubuntu:Pro:20.04:LTS: libvirt, Ubuntu:22.04:LTS: libvirt, Ubuntu:24.04:LTS: libvirt, Ubuntu:26.04:LTS: libvirt, Ubuntu:26.04:LTS: libvirt-hwe&lt;/p&gt;
&lt;p&gt;A flaw was found in libvirt. During storage volume clone or convert operations, newly created volume images were temporarily world-readable. This was caused by the `qemu-img` utility running with overly permissive file creation settings, allowing any local user to read the full guest disk contents. This vulnerability could lead to sensitive information disclosure from guest virtual machines.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-63623</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2724 — libvirt: Mehrere Schwachstellen ermöglichen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2724</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in libvirt ausnutzen, um Administratorrechte zu erlangen und vertrauliche Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in libvirt ausnutzen, um Administratorrechte zu erlangen und vertrauliche Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2724</guid>
    </item>
  </channel>
</rss>
