CVE Tools

Libvirt

91 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Libvirt, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.

Libvirt CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Libvirt CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-112
2025-120
2026-010
2026-020
2026-030
2026-040
2026-052
2026-060
2026-070
2026-080
2026-090

Severity

How the 91 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical22%
  • High1618%
  • Medium5864%
  • Low1516%

Latest CVEs

The 15 most recently published vulnerabilities affecting Libvirt.

  1. BDU:2026-06224Уязвимость компонента virerror.c библиотеки управления виртуализацией Libvirt, позволяющая нарушителю вызвать отказ в обслуживании5.3
  2. BDU:2026-06228Уязвимость компонента virsocketaddr.c библиотеки управления виртуализацией Libvirt, позволяющая нарушителю вызвать отказ в обслуживании7.5
  3. CVE-2025-13193Libvirt: information disclosure via world-readable vm snapshots5.5
  4. CVE-2025-12748Libvirt: denial of service in xml parsing5.5
  5. CVE-2024-8235Libvirt: crash of virtinterfaced via virconnectlistinterfaces()6.2
  6. CVE-2024-4418Libvirt: stack use-after-free in virnetclientioeventloop()6.2
  7. CVE-2024-2494Libvirt: negative g_new0 length can lead to unbounded memory allocation6.2
  8. CVE-2024-2496Libvirt: null pointer dereference in udevconnectlistallinterfaces()5.0
  9. CVE-2024-1441Libvirt: off-by-one error in udevlistinterfacesbystatus()5.5
  10. CVE-2023-3750Libvirt: improper locking in virstoragepoolobjlistsearch may lead to denial of service6.5
  11. CVE-2023-2700A vulnerability was found in libvirt. This security flaw ouccers due to repeatedly querying an SR-IOV PCI device's capabilities that exposes a memory leak caused by a failure to free the virPCIVirt...5.5
  12. CVE-2021-3975A use-after-free flaw was found in libvirt. The qemuMonitorUnregister() function in qemuProcessHandleMonitorEOF is called using multiple threads without being adequately protected by a monitor lock...6.5
  13. CVE-2022-0897A flaw was found in the libvirt nwfilter driver. The virNWFilterObjListNumOfNWFilters method failed to acquire the driver->nwfilters mutex before iterating over virNWFilterObj instances. There was ...4.3
  14. CVE-2021-4147A flaw was found in the libvirt libxl driver. A malicious guest could continuously reboot itself and cause libvirtd on the host to deadlock or crash, resulting in a denial of service condition.6.5
  15. CVE-2021-3667An improper locking issue was found in the virStoragePoolLookupByTargetPath API of libvirt. It occurs in the storagePoolLookupByTargetPath function where a locked virStoragePoolObj object is not pr...6.5

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store