CVE-2025-13193
published 2025-11-17CVE-2025-13193: A flaw was found in libvirt. External inactive snapshots for shut-down VMs are incorrectly created as world-readable, making it possible for unprivileged users…
PriorityP425medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.12%
2.0th percentile
A flaw was found in libvirt. External inactive snapshots for shut-down VMs are incorrectly created as world-readable, making it possible for unprivileged users to inspect the guest OS contents. This results in an information disclosure vulnerability.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libvirt | < libvirt 11.10.0-1 (forky) | libvirt 11.10.0-1 (forky) |
| msrc | azl3_libvirt_10.0.0-5_on_azure_linux_3.0 | — | — |
| msrc | azl3_libvirt_10.0.0-6_on_azure_linux_3.0 | — | — |
| redhat | libvirt | >= 0 < 11.3.0-3+deb13u2 | 11.3.0-3+deb13u2 |
| redhat | libvirt | >= 0 < 11.10.0-1 | 11.10.0-1 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libvirt vulnerabilities
vendor_ubuntu·2026-01-08·CVSS 5.5
CVE-2025-13193 [MEDIUM] libvirt vulnerabilities
Title: libvirt vulnerabilities
Summary: Several security issues were fixed in libvirt.
It was discovered that libvirt parsed user-provided XML files before
performing ACL checks. An attacker could possibly use this issue to cause
libvirt to consume memory, resulting in a denial of service.
(CVE-2025-12748)
It was discovered that libvirt incorrectly handled permissions on external
inactive snapshots. A local attacker could possibly use this issue to
obtain sensitive guest contents. (CVE-2025-13193)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Red Hat
libvirt: Information disclosure via world-readable VM snapshots
vendor_redhat·2025-11-12·CVSS 5.5
CVE-2025-13193 [MEDIUM] CWE-276 libvirt: Information disclosure via world-readable VM snapshots
libvirt: Information disclosure via world-readable VM snapshots
A flaw was found in libvirt. External inactive snapshots for shut-down VMs are incorrectly created as world-readable, making it possible for unprivileged users to inspect the guest OS contents. This results in an information disclosure vulnerability.
A flaw was found in libvirt. External inactive snapshots for shut-down VMs are incorrectly created as world-readable, making it possible for unprivileged users to inspect the guest OS contents. This results in an information disclosure vulnerability.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base
Microsoft
Libvirt: information disclosure via world-readable vm snapshots
vendor_msrc·2025-11-11·CVSS 5.5
CVE-2025-13193 [MEDIUM] CWE-276 Libvirt: information disclosure via world-readable vm snapshots
Libvirt: information disclosure via world-readable vm snapshots
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade
Debian
CVE-2025-13193: libvirt - A flaw was found in libvirt. External inactive snapshots for shut-down VMs are i...
vendor_debian·2025·CVSS 5.5
CVE-2025-13193 [MEDIUM] CVE-2025-13193: libvirt - A flaw was found in libvirt. External inactive snapshots for shut-down VMs are i...
A flaw was found in libvirt. External inactive snapshots for shut-down VMs are incorrectly created as world-readable, making it possible for unprivileged users to inspect the guest OS contents. This results in an information disclosure vulnerability.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 11.10.0-1)
sid: resolved (fixed in 11.10.0-1)
trixie: resolved (fixed in 11.3.0-3+deb13u2)
OSV
CVE-2025-13193: A flaw was found in libvirt
osv·2025-11-17·CVSS 5.5
CVE-2025-13193 [MEDIUM] CVE-2025-13193: A flaw was found in libvirt
A flaw was found in libvirt. External inactive snapshots for shut-down VMs are incorrectly created as world-readable, making it possible for unprivileged users to inspect the guest OS contents. This results in an information disclosure vulnerability.
GHSA
GHSA-223c-8f3h-q9f9: A flaw was found in libvirt
ghsa_unreviewed·2025-11-17
CVE-2025-13193 [MEDIUM] CWE-276 GHSA-223c-8f3h-q9f9: A flaw was found in libvirt
A flaw was found in libvirt. External inactive snapshots for shut-down VMs are incorrectly created as world-readable, making it possible for unprivileged users to inspect the guest OS contents. This results in an information disclosure vulnerability.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-11-17
Published