{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/vendors/libvirt/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.8,"id":"CVE-2026-63622"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["libvirt"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Libvirt"],"content_html":"\u003cp\u003eA vulnerability identified as CVE-2026-63622 exists within the libvirt management library, specifically involving the \u003ccode\u003evirFileChownFiles()\u003c/code\u003e function. The flaw enables a local attacker, operating under the constrained \u003ccode\u003eswtpm\u003c/code\u003e user context, to perform unauthorized file ownership changes. By creating malicious symbolic links within the \u003ccode\u003eswtpm\u003c/code\u003e state directory, an attacker can influence the libvirt daemon - which runs with root privileges - to perform a chown operation on arbitrary files on the host system. This mechanism effectively breaks the sandbox isolation, allowing the \u003ccode\u003eswtpm\u003c/code\u003e process to gain ownership of system files, thereby facilitating privilege escalation to root-level file access. This vulnerability is significant for environments leveraging virtual machine TPM emulation.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows a low-privileged \u003ccode\u003eswtpm\u003c/code\u003e process to gain ownership over arbitrary files on the host filesystem. This impact is critical in multi-tenant environments or systems relying on libvirt for virtualization security, as it provides a pathway for the attacker to manipulate security-sensitive files, bypass access controls, or escalate privileges to full root access depending on the target file selected for ownership transition.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eApply vendor-supplied patches for the libvirt library immediately to address CVE-2026-63622.\u003c/li\u003e\n\u003cli\u003eAudit the \u003ccode\u003eswtpm\u003c/code\u003e state directory locations on virtualization hosts for unusual symbolic link creations.\u003c/li\u003e\n\u003cli\u003eImplement stricter SELinux or AppArmor profiles for the \u003ccode\u003eswtpm\u003c/code\u003e process to restrict file system access outside of designated state directories.\u003c/li\u003e\n\u003cli\u003eMonitor for unexpected calls to \u003ccode\u003echown\u003c/code\u003e or \u003ccode\u003efchown\u003c/code\u003e initiated by the \u003ccode\u003elibvirtd\u003c/code\u003e process.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-10T21:40:21Z","date_published":"2026-08-10T21:40:21Z","id":"https://feed.craftedsignal.io/briefs/2026-08-libvirt-symlink-priv-esc/","summary":"A local privilege escalation vulnerability in libvirt allows a confined swtpm process to trick the libvirt daemon into changing file ownership through symlink following, potentially granting root-level file access.","title":"Local Privilege Escalation in libvirt via Symlink Following (CVE-2026-63622)","url":"https://feed.craftedsignal.io/briefs/2026-08-libvirt-symlink-priv-esc/"}],"language":"en","title":"CraftedSignal Threat Feed - Libvirt","version":"https://jsonfeed.org/version/1.1"}