CVE-2026-77159

ADVISORY - nist

Summary

A symlink-following flaw was found in libvirt's qemuTPMEmulatorPrepareHost() function. The function uses a path-based chown() on the swtpm logfile without checking for symbolic links. A local attacker with access to the swtpm account can replace the logfile with a symlink, causing libvirtd (running as root) to transfer ownership of an arbitrary file to the swtpm user.

Common Weakness Enumeration (CWE)

ADVISORY - nist

UNIX Symbolic Link (Symlink) Following

ADVISORY - redhat

UNIX Symbolic Link (Symlink) Following


Sign in to Docker Scout

See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.

Sign in