Impact
A symlink‑following flaw in libvirt’s qemuTPMEmulatorPrepareHost() allows a local attacker controlling the swtpm account to replace the swtpm log file with a symbolic link. When libvirtd, running as root, calls chown on that path, it follows the link and changes ownership of the target file to the swtpm user. The attacker can thus transfer ownership of arbitrary files that normally belong to root, creating a local privilege escalation path.
Affected Systems
Red Hat Enterprise Linux release 6 through 10, when running libvirt, are impacted. All components that employ the qemuTPMEmulatorPrepareHost() service are potentially affected. No other vendor products are indicated.
Risk and Exploitability
The CVSS base score is 5.5, indicating medium severity. The EPSS score is not available and the flaw is not listed in the CISA KEV database, suggesting limited or no observed exploitation. It is inferred that the attack vector is local; an attacker must control the swtpm account or have write access to the swtpm log file. SELinux in enforcing mode confines swtpm to the swtpm_t domain, preventing creation of arbitrary symlinks and thereby reducing the attack surface. In configurations where SELinux is disabled or set to permissive mode, the flaw can be fully leveraged to modify file ownership.
OpenCVE Enrichment
Ubuntu USN