What is CVE-2026-63622?
A flaw in libvirt tracked as CVE-2026-63622 allows a local attacker, running as the confined `swtpm` user, to exploit a symlink-following vulnerability in the `virFileChownFiles()` function. By placing a symbolic link in the `swtpm` state directory, the attacker could manipulate file ownership with root-level privileges. Immediate libvirt updates are required.
Azərbaycanca: libvirt-də tapılan CVE-2026-63622 zəifliyi, `swtpm` istifadəçisi kimi işləyən lokal təcavüzkara `virFileChownFiles()` funksiyasında simvolik keçid izləmə (symlink-following) vasitəsilə fayl sahibliyini dəyişməyə imkan verir. Bu, təcavüzkarın root səviyyəsində imtiyaz əldə etməsinə səbəb ola bilər. Ən qısa zamanda libvirt yeniləməsi tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
What privilege level can a local attacker gain by exploiting CVE-2026-63622?
The attacker could obtain root-level privileges.
In which libvirt function does the symlink-following vulnerability in CVE-2026-63622 occur?
The vulnerability is in the `virFileChownFiles()` function.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.