PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-63622 Red Hat CVE debrief

A local attacker could exploit a symlink-following vulnerability in libvirt's `virFileChownFiles()` function to escalate privileges from the `swtpm` sandbox to root-level file ownership control. This vulnerability allows a process running as the confined `swtpm` user to plant a symbolic link within the `swtpm` state directory, tricking the root-level libvirt daemon into changing the ownership of an arbitrary file to the `swtpm` user, potentially leading to privilege escalation. System administrators and security teams should assess exposure and prioritize remediation for systems using libvirt, especially those with access to the `swtpm` state directory.

Vendor
Red Hat
Product
Red Hat Enterprise Linux 10.0 Extended Update Support
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-10
Original CVE updated
2026-09-08
Advisory published
2026-08-10
Advisory updated
2026-09-08

Who should care

System administrators and security teams responsible for systems using libvirt, especially those with access to the `swtpm` state directory, should assess exposure and prioritize remediation.

Why it matters

A local attacker could exploit a symlink-following vulnerability in libvirt's `virFileChownFiles()` function to escalate privileges, requiring system administrators to assess exposure and prioritize remediation.

  • Privilege escalation from the `swtpm` sandbox to root-level file ownership control
  • Potential for local attackers to gain elevated privileges
  • Need for system administrators to assess exposure and prioritize remediation

Technical summary

A flaw in libvirt's `virFileChownFiles()` function allows a local attacker to exploit a symlink-following vulnerability, potentially leading to privilege escalation from the `swtpm` sandbox to root-level file ownership control. The vulnerability is due to a process running as the confined `swtpm` user being able to plant a symbolic link within the `swtpm` state directory, tricking the root-level libvirt daemon into changing the ownership of an arbitrary file to the `swtpm` user. This allows for potential privilege escalation and requires system administrators to assess exposure and prioritize remediation.

Defensive priority

Assess exposure and prioritize remediation for systems using libvirt, especially where the confined `swtpm` user has access to the `swtpm` state directory.

Recommended defensive actions

  • Assess systems using libvirt for exposure to the `swtpm` state directory
  • Prioritize remediation for systems where the confined `swtpm` user has access to the `swtpm` state directory
  • Monitor for local attacks attempting to exploit this vulnerability
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide details on the vulnerability. Red Hat has published errata and security advisories related to this issue. The vulnerability was publicly disclosed on 2026-08-10 and affects libvirt. There are no known exploits in the wild, but defenders should verify affected scope and vendor guidance. Limited source detail is available; explicit evidence limits apply.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-63622 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-63622

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-63622 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-63622

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.