Known vulnerabilities in libvirt

Software: libvirt
Software CPE: cpe:2.3:a:libvirt_org:libvirt:*:*:*:*:*:*:*:*
Website:
Total vulnerabilities: 58
Public exploits: 3
Known exploited (KEV): 0
Highest CVSSv4 Score: 8.8

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting libvirt libvirt is affected by 58 known vulnerabilities: 2 high, 24 medium, 32 low Critical High Medium Low

Vulnerabilities (58)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU118836 - Incorrect Default Permissions
CVE-2025-13193
CWE-276 Medium
No
No
- 28.11.2025 SB2025112859
SB2025112864
SB2025120519
and 12 more
#VU118835 - Resource exhaustion
CVE-2025-12748
CWE-400 Medium
No
No
- 28.11.2025 SB2025112859
SB2025112864
SB2025120541
and 12 more
#VU100250 - NULL Pointer Dereference
CVE-2024-8235
CWE-476 Low
No
No
10.7.0 12.11.2024 SB2024111272
SB2024111274
#VU89356 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2024-4418
CWE-362 Low
No
No
10.3.0 10.05.2024 SB2024051051
SB2024051053
SB2024060443
and 13 more
#VU88535 - NULL Pointer Dereference
CVE-2024-2496
CWE-476 Low
No
No
9.8.0 15.04.2024 SB2024041541
SB2024041542
SB2024043065
and 3 more
#VU87970 - Uncontrolled Memory Allocation
CVE-2024-2494
CWE-789 Low
No
No
- 02.04.2024 SB2024040216
SB2024040222
SB2024040231
and 9 more
#VU87448 - Off-by-one Error
CVE-2024-1441
CWE-193 Low
No
No
10.1.0 12.03.2024 SB20240312330
SB20240312332
SB20240312333
and 6 more
#VU78694 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2023-3750
CWE-362 Medium
No
No
- 26.07.2023 SB2023072647
SB2023072649
SB2023073149
and 4 more
#VU76721 - Missing release of memory after effective lifetime
CVE-2023-2700
CWE-401 Low
No
No
9.3.0 31.05.2023 SB2023053145
SB2023053152
SB2023060225
and 12 more
#VU62739 - Improper Locking
CVE-2022-0897
CWE-667 Medium
No
No
8.2.0 03.05.2022 SB2022050304
SB2022050308
SB2022101708
and 8 more
#VU62735 - Incorrect Permission Assignment for Critical Resource
CVE-2021-3631
CWE-732 Medium
No
No
7.5.0 03.05.2022 SB2022050302
SB2022050308
SB2021072782
and 6 more
#VU62734 - Improper Locking
CVE-2021-3667
CWE-667 Low
No
No
7.6.0 03.05.2022 SB2022050303
SB2022050308
SB2021082320
and 7 more
#VU58358 - Use After Free
CVE-2021-3975
CWE-416 Low
No
No
7.1.0 24.11.2021 SB2021112416
SB2021112418
SB2022050308
and 8 more
#VU48591 - Double Free
CVE-2020-25637
CWE-415 Low
Available
No
6.8.0 06.10.2020 SB2020112301
SB2020112303
SB2020112432
and 7 more
#VU46198 - Exposure of sensitive information to an unauthorized actor
CVE-2020-14339
CWE-200 Medium
No
No
6.6.0 01.09.2020 SB2020090128
SB2020081714
SB2020091907
and 6 more
#VU31937 - Exposure of sensitive information to an unauthorized actor
CVE-2020-14301
CWE-200 Low
No
No
6.3.0 27.07.2020 SB2020041498
SB2020110507
SB2025032962
#VU28191 - Resource Management Errors
CVE-2020-10703
CWE-399 Low
No
No
6.0.0 23.05.2020 SB2020031934
SB2020052305
SB2020093025
and 2 more
#VU27545 - Resource Management Errors
CVE-2019-20485
CWE-399 Medium
No
No
6.0.0 05.05.2020 SB2020031934
SB2020093025
SB2020110507
and 1 more
#VU27541 - Missing release of memory after effective lifetime
CVE-2020-12430
CWE-401 Medium
No
No
6.1.0 05.05.2020 SB2020050513
SB2020052305
SB2020051287
and 1 more
#VU32020 - Improper Access Control
CVE-2019-10168
CWE-284 Low
No
No
- 02.08.2019 SB2019080215
SB2019072014
SB2019070323
and 7 more


Showing elements 1 - 20 out of 58