在 libvirt 的 函数中发现了一个符号链接跟随(symlink-following)漏洞。该函数在对 swtpm 日志文件执行基于路径的 操作时,未检查该文件是否为符号链接。因此,拥有 swtpm 账户访问权限的本地攻击者可以将该日志文件替换为一个符号链接,从而让以 root 身份运行的 libvirtd 将任意文件的所有权转移给 swtpm 用户。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-89060 | 7.7 HIGH | Stolostron/multicluster-observability-addon: cross-namespace secret disclosure in multiclu |
| CVE-2026-18495 | 6.1 MEDIUM | Libtiff: libtiff: heap-buffer overflow via numeric truncation in the jpeg raw passthrough |
| CVE-2026-89298 | 4.9 MEDIUM | Keycloak-services: keycloak-services: confidential client secret disclosed to view-clients |
| CVE-2026-88914 | 4.4 MEDIUM | Gstreamer1-plugins-good: gstreamer: integer overflow and out-of-bounds read in qtdemux cea |
No comments yet