PT-2025-46530 · Red Hat+3 · Libvirt+3

Published

2024-10-01

·

Updated

2026-05-19

·

CVE-2025-12748

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions libvirt (affected versions not specified)
Description A flaw exists in libvirt related to XML file processing. Specifically, user-provided XML files are parsed before Access Control List (ACL) checks. A malicious user with limited permissions could exploit this by submitting a crafted XML file, leading to excessive memory allocation on the host. This excessive memory consumption could cause a libvirt process crash, resulting in a denial-of-service condition.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

ALSA-2026:18326
ALSA-2026:18748
AZL-70187
AZL-70199
BDU:2025-16420
CVE-2025-12748
OESA-2025-2812
OPENSUSE-SU-2025:15746-1
OPENSUSE-SU-2025:20100-1
RHSA-2026:18326
RHSA-2026:18748
SUSE-SU-2025:21082-1
SUSE-SU-2025:21150-1
SUSE-SU-2025_21150-1
SUSE-SU-2026:0068-1
SUSE-SU-2026:0079-1
SUSE-SU-2026:0080-1
SUSE-SU-2026:0193-1
SUSE-SU-2026:0279-1
SUSE-SU-2026:0375-1
SUSE-SU-2026:20050-1
SUSE-SU-2026:21263-1
USN-7047-1

Affected Products

Alt Linux
Debian
Suse
Libvirt