libvirt是libvirt组织开源的一个虚拟化平台管理工具。 libvirt存在权限许可和访问控制问题漏洞,该漏洞源于qemu-img工具运行时的文件创建设置过于宽松,导致存储卷克隆或转换操作期间新创建的卷镜像暂时全局可读,可能允许任何本地用户读取完整客户机磁盘内容,造成敏感信息泄露。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 6 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 7 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 8 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 9 | any |
affected |
| Red Hat | Red Hat Enterprise Linux for NVIDIA 26 | any |
unknown |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| Red Hat | Red Hat Enterprise Linux for NVIDIA 26 | - |
cpe:/a:redhat:enterprise_linux_nvidia:
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-18948 | 9.9 CRITICAL | Feast: feast: unsafe dill deserialization of registry-stored udfs — rce on feature server |
| CVE-2026-14450 | 9.9 CRITICAL | Maas-billing: maas api: privilege escalation via forged http headers due to missing authen |
| CVE-2026-18951 | 8.8 HIGH | Odh-training-operator-rhel9: [trainer v2 security] trn-02: rhoai overlay aggregates trainj |
| CVE-2026-18950 | 8.8 HIGH | Odh-dashboard: odh-dashboard: confused-deputy privilege escalation via unchecked roleref i |
| CVE-2026-18949 | 8.8 HIGH | Odh-dashboard: odh-dashboard: clusterrole grants cluster-wide crud on secrets and rbac man |
| CVE-2026-18982 | 8.8 HIGH | Odh-training-operator-rhel9: rhoai fork aggregates training job create onto native edit/ad |
| CVE-2026-18617 | 8.8 HIGH | Data-science-pipelines-operator: dspo: mysql dsn parameter injection via customextraparams |
| CVE-2026-18608 | 8.7 HIGH | Data-science-pipelines-operator: dspo: operator clusterrole grants pods/exec:*, kubeflow.o |
| CVE-2026-18947 | 8.5 HIGH | Feast: feast: authorization bypass in /materialize endpoints enables dos via unauthorized |
| CVE-2026-71576 | 8.5 HIGH | Multicluster-global-hub: multicluster-global-hub: manager trusts self-asserted evt.source( |
| CVE-2026-15467 | 8.1 HIGH | Trustyai-service-operator: trustyai-service-operator: lmevaljob sidecar containers bypass |
| CVE-2026-15581 | 8.0 HIGH | Trustyai-service-operator: trustyai-service-operator: tas internal service bypasses kube-r |
| CVE-2026-63622 | 7.8 HIGH | Libvirt: swtpm privilege escalation via symlink following |
| CVE-2026-18941 | 7.7 HIGH | Feast: feast-operator: feast: default authentication mode is no_auth — shared multi-tenant |
| CVE-2026-18621 | 7.6 HIGH | Data-sciences-pipeline: dsp: v1 argo template path accepts arbitrary workflow spec, bypass |
| CVE-2026-19387 | 7.6 HIGH | Gstreamer: gstreamer1-plugins-bad-free: gstreamer: heap out-of-bounds write in adpcmdec im |
| CVE-2026-18611 | 7.5 HIGH | Data-science-pipelines-operator: dspo: cryptographically weak secret generation (math/rand |
| CVE-2026-18618 | 7.5 HIGH | Ml-metdata: bundled grpc 1.46.3 (2022) with published http/2 dos cves — directly reachable |
| CVE-2026-19389 | 7.1 HIGH | Gstreamer: gstreamer1-plugins-ugly-free: gstreamer: integer overflow/underflow in asfdemux |
| CVE-2026-18620 | 7.1 HIGH | Data-sciences-pipeline: user-controlled serviceaccount for workflow pods without authoriza |
Showing top 20 of 28 CVEs. View all on vendor page → →
No comments yet