Libvirt
91 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Libvirt, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.
Libvirt CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 2 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 2 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 91 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical2
- High16
- Medium58
- Low15
Latest CVEs
The 15 most recently published vulnerabilities affecting Libvirt.
- BDU:2026-06224Уязвимость компонента virerror.c библиотеки управления виртуализацией Libvirt, позволяющая нарушителю вызвать отказ в обслуживании5.3
- BDU:2026-06228Уязвимость компонента virsocketaddr.c библиотеки управления виртуализацией Libvirt, позволяющая нарушителю вызвать отказ в обслуживании7.5
- CVE-2025-13193Libvirt: information disclosure via world-readable vm snapshots5.5
- CVE-2025-12748Libvirt: denial of service in xml parsing5.5
- CVE-2024-8235Libvirt: crash of virtinterfaced via virconnectlistinterfaces()6.2
- CVE-2024-4418Libvirt: stack use-after-free in virnetclientioeventloop()6.2
- CVE-2024-2494Libvirt: negative g_new0 length can lead to unbounded memory allocation6.2
- CVE-2024-2496Libvirt: null pointer dereference in udevconnectlistallinterfaces()5.0
- CVE-2024-1441Libvirt: off-by-one error in udevlistinterfacesbystatus()5.5
- CVE-2023-3750Libvirt: improper locking in virstoragepoolobjlistsearch may lead to denial of service6.5
- CVE-2023-2700A vulnerability was found in libvirt. This security flaw ouccers due to repeatedly querying an SR-IOV PCI device's capabilities that exposes a memory leak caused by a failure to free the virPCIVirt...5.5
- CVE-2021-3975A use-after-free flaw was found in libvirt. The qemuMonitorUnregister() function in qemuProcessHandleMonitorEOF is called using multiple threads without being adequately protected by a monitor lock...6.5
- CVE-2022-0897A flaw was found in the libvirt nwfilter driver. The virNWFilterObjListNumOfNWFilters method failed to acquire the driver->nwfilters mutex before iterating over virNWFilterObj instances. There was ...4.3
- CVE-2021-4147A flaw was found in the libvirt libxl driver. A malicious guest could continuously reboot itself and cause libvirtd on the host to deadlock or crash, resulting in a denial of service condition.6.5
- CVE-2021-3667An improper locking issue was found in the virStoragePoolLookupByTargetPath API of libvirt. It occurs in the storagePoolLookupByTargetPath function where a locked virStoragePoolObj object is not pr...6.5
Product grouping is registry-driven, with AI assist and human review. How it works