Impact
A flaw in libvirt causes storage volume images created during clone or convert operations to be temporarily world-readable. The qemu-img utility sets overly permissive file permissions, allowing any local user to read the full guest disk contents. This weakness is described by CWE-732 and results in a moderate-severity information disclosure vulnerability that can expose data stored in virtual machine disks.
Affected Systems
Red Hat Enterprise Linux 10, 6, 7, 8, 9 and Red Hat Enterprise Linux for NVIDIA 26 are affected. No specific version range is listed; all releases of these products that include the vulnerable libvirt code are impacted.
Risk and Exploitability
The CVSS score is 5.5, indicating a moderate severity. Because a local user can access the temporarily world-readable volume image, the attack vector is local, and the vulnerability could lead to sensitive information disclosure from guest virtual machines. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog, so while exploitation is possible, it is not currently widely known or actively exploited.
OpenCVE Enrichment