CVE-2025-13193: Libvirt: information disclosure via world-readable vm snapshots
A flaw was found in libvirt. External inactive snapshots for shut-down VMs are incorrectly created as world-readable, making it possible for unprivileged users to inspect the guest OS contents. This results in an information disclosure vulnerability.
Other sources
External inactive snapshots for shut-down VMs are incorrectly created as world-readable, making it possible for unprivileged users to inspect the guest OS contents. This results in an information disclosure vulnerability.
Debian bug: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1120119
Upstream patch: https://gitlab.com/libvirt/libvirt/-/commit/a379327d8abcde8ac8d3e16fe5e4ba6f790d767a
— Red Hat
Libvirt: information disclosure via world-readable vm snapshots
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/libvirtto a version that resolves this vulnerability.Fixed in 7.0.0-3+deb11u3Fixed in 9.0.0-4+deb12u2Fixed in 11.10.0-1 - Upgrade
Upgrade
libvirtto a version that resolves this vulnerability.Patch a379327d8abcde8ac8d3e16fe5e4ba6f790d767a
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13193?
CVE-2025-13193 is classified as an information disclosure vulnerability due to external inactive snapshots being world-readable.
How do I fix CVE-2025-13193?
To mitigate CVE-2025-13193, upgrade the libvirt package to versions 11.3.0-3+deb13u1 or 11.9.0-2 or higher.
Who is affected by CVE-2025-13193?
CVE-2025-13193 affects users of libvirt versions up to and including 11.3.0-3 and versions up to 9.7.0-1.
What impact does CVE-2025-13193 have?
CVE-2025-13193 allows unprivileged users to inspect guest OS contents through improperly secured snapshots.
Is CVE-2025-13193 related to virtualization security?
Yes, CVE-2025-13193 directly impacts virtualization security by exposing sensitive data from inactive snapshots.