Red HatCVE-2026-63622
Red Hat Enterprise Linux 10: privilege escalation
High7.8CVE-2026-63622 · Published Aug 10, 2026 · updated Sep 21, 2026
A flaw was found in libvirt. A local attacker, specifically a process running as the confined `swtpm` user, could exploit a symlink-following vulnerability in the `virFileChownFiles()` function. By planting a symbolic link within the `swtpm` state directory, the attacker could trick the root-level libvirt daemon into changing the ownership of an arbitrary file to the `swtpm` user. This allows for privilege escalation from the `swtpm` sandbox to root-level file ownership control.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Red Hat Enterprise Linux 10 Product | all versions | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-59
- www.cve.org/CVERecord?id=CVE-2026-63622
- nvd.nist.gov/vuln/detail/CVE-2026-63622
- access.redhat.com/errata/RHSA-2026:64773
- access.redhat.com/errata/RHSA-2026:65515
- access.redhat.com/errata/RHSA-2026:65516
- access.redhat.com/errata/RHSA-2026:65803
- access.redhat.com/errata/RHSA-2026:68513
- access.redhat.com/errata/RHSA-2026:68594
- access.redhat.com/errata/RHSA-2026:69114
- access.redhat.com/errata/RHSA-2026:69131
- access.redhat.com/security/cve/CVE-2026-63622
- bugzilla.redhat.com/show_bug.cgi?id=2513065
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 10 | Red Hat QEMU: memory corruption | Medium4.4 | No fix yet |
| Aug 10 | Red Hat Enterprise Linux: denial of service | Low3.9 | No fix yet |
| Aug 10 | Red Hat OpenShift AI (RHOAI): denial of service | High8.5 | No fix yet |
| Aug 10 | Red Hat OpenShift AI (RHOAI): remote code execution | Critical9.9 | No fix yet |
| Aug 10 | Red Hat OpenShift AI (RHOAI): privilege escalation | High8.8 | No fix yet |
| Aug 10 | Red Hat OpenShift AI (RHOAI): privilege escalation | High8.8 | No fix yet |