Description
A symlink-following flaw was found in libvirt's qemuTPMEmulatorPrepareHost() function. The function uses a path-based chown() on the swtpm logfile without checking for symbolic links. A local attacker with access to the swtpm account can replace the logfile with a symlink, causing libvirtd (running as root) to transfer ownership of an arbitrary file to the swtpm user.
Published: 2026-09-11
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Enable SELinux
AI Analysis

Impact

A symlink‑following flaw in libvirt’s qemuTPMEmulatorPrepareHost() allows a local attacker controlling the swtpm account to replace the swtpm log file with a symbolic link. When libvirtd, running as root, calls chown on that path, it follows the link and changes ownership of the target file to the swtpm user. The attacker can thus transfer ownership of arbitrary files that normally belong to root, creating a local privilege escalation path.

Affected Systems

Red Hat Enterprise Linux release 6 through 10, when running libvirt, are impacted. All components that employ the qemuTPMEmulatorPrepareHost() service are potentially affected. No other vendor products are indicated.

Risk and Exploitability

The CVSS base score is 5.5, indicating medium severity. The EPSS score is not available and the flaw is not listed in the CISA KEV database, suggesting limited or no observed exploitation. It is inferred that the attack vector is local; an attacker must control the swtpm account or have write access to the swtpm log file. SELinux in enforcing mode confines swtpm to the swtpm_t domain, preventing creation of arbitrary symlinks and thereby reducing the attack surface. In configurations where SELinux is disabled or set to permissive mode, the flaw can be fully leveraged to modify file ownership.

Generated by OpenCVE AI on September 11, 2026 at 13:25 UTC.

Remediation

Vendor Workaround

On Red Hat Enterprise Linux, SELinux in enforcing mode (the default) confines the swtpm process to the swtpm_t domain, which restricts the creation of symlinks to arbitrary file types and limits the scope of any ownership change, reducing the practical impact of this flaw. Ensure SELinux is not disabled or set to permissive mode.


OpenCVE Recommended Actions

  • Ensure SELinux is configured in enforcing mode and is not set to permissive or disabled; this confines the swtpm process and limits symlink creation.
  • Restrict local access to the swtpm account by disabling its login capabilities and applying the least‑privilege principle; prevent ordinary users from writing into its log directory.
  • Verify that the directory containing the swtpm log file and the log file itself are owned by root and are not writable by untrusted users; if necessary, adjust permissions or move the log to a protected location.
  • Apply any vendor‑issued patch to libvirtemutpmemulatorpreparehost() once it becomes available.

Generated by OpenCVE AI on September 11, 2026 at 13:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Ubuntu USN Ubuntu USN USN-8831-1 libvirt vulnerabilities
Ubuntu USN Ubuntu USN USN-8833-1 libvirt vulnerabilities
History

Tue, 15 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat libvirt
Vendors & Products Redhat libvirt

Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Fri, 11 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description A symlink-following flaw was found in libvirt's qemuTPMEmulatorPrepareHost() function. The function uses a path-based chown() on the swtpm logfile without checking for symbolic links. A local attacker with access to the swtpm account can replace the logfile with a symlink, causing libvirtd (running as root) to transfer ownership of an arbitrary file to the swtpm user.
Title Libvirt: unsafe chown in qemutpmemulatorpreparehost() allows arbitrary file ownership change via symlink
First Time appeared Redhat
Redhat enterprise Linux
Weaknesses CWE-61
CPEs cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

Redhat Enterprise Linux Libvirt
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-15T15:40:56.022Z

Reserved: 2026-08-20T14:42:32.943Z

Link: CVE-2026-77159

cve-icon Vulnrichment

Updated: 2026-09-15T15:39:27.229Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-11T11:16:54.677

Modified: 2026-09-16T19:42:43.623

Link: CVE-2026-77159

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T00:00:00Z

Links: CVE-2026-77159 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T19:56:30Z

Weaknesses
  • CWE-61

    UNIX Symbolic Link (Symlink) Following