High severity7.8NVD Advisory· Published Aug 10, 2026· Updated Sep 21, 2026
CVE-2026-63622
CVE-2026-63622
Description
A flaw was found in libvirt. A local attacker, specifically a process running as the confined swtpm user, could exploit a symlink-following vulnerability in the virFileChownFiles() function. By planting a symbolic link within the swtpm state directory, the attacker could trick the root-level libvirt daemon into changing the ownership of an arbitrary file to the swtpm user. This allows for privilege escalation from the swtpm sandbox to root-level file ownership control.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
10- access.redhat.com/errata/RHSA-2026:64773nvd
- access.redhat.com/errata/RHSA-2026:65515nvd
- access.redhat.com/errata/RHSA-2026:65516nvd
- access.redhat.com/errata/RHSA-2026:65803nvd
- access.redhat.com/errata/RHSA-2026:68513nvd
- access.redhat.com/errata/RHSA-2026:68594nvd
- access.redhat.com/errata/RHSA-2026:69114nvd
- access.redhat.com/errata/RHSA-2026:69131nvd
- access.redhat.com/security/cve/CVE-2026-63622nvd
- bugzilla.redhat.com/show_bug.cginvd
News mentions
0No linked articles in our index yet.