A flaw was found in libvirt. External inactive snapshots for shut-down VMs are incorrectly created as world-readable, making it possible for unprivileged users to inspect the guest OS contents. This results in an information disclosure vulnerability.
During installation, installed file permissions are set to allow anyone to modify those files.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Libvirt | Ubuntu | devel | * |
| Libvirt | Ubuntu | esm-infra-legacy/trusty | * |
| Libvirt | Ubuntu | esm-infra-legacy/xenial | * |
| Libvirt | Ubuntu | esm-infra/bionic | * |
| Libvirt | Ubuntu | esm-infra/focal | * |
| Libvirt | Ubuntu | esm-infra/xenial | * |
| Libvirt | Ubuntu | jammy | * |
| Libvirt | Ubuntu | noble | * |
| Libvirt | Ubuntu | plucky | * |
| Libvirt | Ubuntu | questing | * |
| Libvirt | Ubuntu | resolute | * |