Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4989 articles · 189008 vulns · 37/41 feeds (7d)
← Back to list
5.5
CVE-2026-63623EXPLOITED
red hat · red hat enterprise linux

Libvirt: information disclosure via world-readable storage volume images during clone/convert

Description

A flaw was found in libvirt. During storage volume clone or convert operations, newly created volume images were temporarily world-readable. This was caused by the `qemu-img` utility running with overly permissive file creation settings, allowing any local user to read the full guest disk contents. This vulnerability could lead to sensitive information disclosure from guest virtual machines.

Affected Products

VendorProductVersions
red hatred hat enterprise linux—

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
open sourceopen source libvirtcert_advisory90%

References

  • https://access.redhat.com/security/cve/CVE-2026-63623(vdb-entry, x_refsource_REDHAT)
  • https://bugzilla.redhat.com/show_bug.cgi?id=2513066(issue-tracking, x_refsource_REDHAT)

Related News (2 articles)

Tier B
BSI Advisories1d ago
[NEU] [mittel] libvirt: Mehrere Schwachstellen ermöglichen
→ No new info (linked only)
Tier C
VulDB2d ago
CVE-2026-63623 | Red Hat Enterprise Linux libvirt information disclosure
→ No new info (linked only)
CVSS 3.15.5 NONE
CISA KEV❌ No
Actively exploited✅ Yes
CWECWE-732
PublishedAug 10, 2026
Last enriched2d ago
Tags
remote code executionfile manipulationdenial of servicemultiple vulnerabilities
Trending Score42
Source articles2
Independent2
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-4480EXPKEV
Samba: samba: remote code execution in printing subsystem via unescaped job description
Trending: 48
NONECVE-2026-59091EXP
Gimp: gimp: multiple vulnerabilities in file format plugins via crafted image file
Trending: 47
MEDIUMCVE-2026-6426EXP
Qemu-kvm: vhost inflight migration vmstate integer type mismatch causes out-of-bounds access
Trending: 45
NONECVE-2026-59090EXP
Gimp: gimp: arbitrary code execution in psd plugin due to unsigned underflow
Trending: 44
NONECVE-2026-59088EXP
Gimp: gimp: denial of service via signed integer overflow in fli file processing
Trending: 43

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 10, 2026
Discovered by ZDM
Aug 10, 2026
Actively Exploited
Aug 10, 2026
Exploit Available
Aug 10, 2026