PatchSiren cyber security CVE debrief
CVE-2026-63622 Red Hat CVE debrief
A local attacker could exploit a symlink-following vulnerability in libvirt's `virFileChownFiles()` function to escalate privileges from the `swtpm` sandbox to root-level file ownership control. This vulnerability allows a process running as the confined `swtpm` user to plant a symbolic link within the `swtpm` state directory, tricking the root-level libvirt daemon into changing the ownership of an arbitrary file to the `swtpm` user, potentially leading to privilege escalation. System administrators and security teams should assess exposure and prioritize remediation for systems using libvirt, especially those with access to the `swtpm` state directory.
- Vendor
- Red Hat
- Product
- Red Hat Enterprise Linux 10.0 Extended Update Support
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-10
- Original CVE updated
- 2026-09-08
- Advisory published
- 2026-08-10
- Advisory updated
- 2026-09-08
Who should care
System administrators and security teams responsible for systems using libvirt, especially those with access to the `swtpm` state directory, should assess exposure and prioritize remediation.
Why it matters
A local attacker could exploit a symlink-following vulnerability in libvirt's `virFileChownFiles()` function to escalate privileges, requiring system administrators to assess exposure and prioritize remediation.
- Privilege escalation from the `swtpm` sandbox to root-level file ownership control
- Potential for local attackers to gain elevated privileges
- Need for system administrators to assess exposure and prioritize remediation
Technical summary
A flaw in libvirt's `virFileChownFiles()` function allows a local attacker to exploit a symlink-following vulnerability, potentially leading to privilege escalation from the `swtpm` sandbox to root-level file ownership control. The vulnerability is due to a process running as the confined `swtpm` user being able to plant a symbolic link within the `swtpm` state directory, tricking the root-level libvirt daemon into changing the ownership of an arbitrary file to the `swtpm` user. This allows for potential privilege escalation and requires system administrators to assess exposure and prioritize remediation.
Defensive priority
Assess exposure and prioritize remediation for systems using libvirt, especially where the confined `swtpm` user has access to the `swtpm` state directory.
Recommended defensive actions
- Assess systems using libvirt for exposure to the `swtpm` state directory
- Prioritize remediation for systems where the confined `swtpm` user has access to the `swtpm` state directory
- Monitor for local attacks attempting to exploit this vulnerability
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD entry provide details on the vulnerability. Red Hat has published errata and security advisories related to this issue. The vulnerability was publicly disclosed on 2026-08-10 and affects libvirt. There are no known exploits in the wild, but defenders should verify affected scope and vendor guidance. Limited source detail is available; explicit evidence limits apply.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-63622 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-63622
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-63622 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-63622
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:64773
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/security/cve/CVE-2026-63622
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.