On a Tuesday in 2026, Daniel P. Berrangé via Devel wrote:
From: HE WEI(ギカク) <[email protected]>On the local (non-NETFS) path virStorageBackendCreateExecCommand() ran qemu-img with umask 0, so the destination image was created world-readable (0644) and the full source disk was written into it before libvirt tightened the mode with a later chmod(). This is the same class as CVE-2025-13193; apply the same fix by setting a 0077 umask so qemu-img creates the file private from the start. Fixes: CVE-2026-63623 Reported-by: HE WEI(ギカク) <[email protected]> Signed-off-by: HE WEI(ギカク) <[email protected]> [DB: merged the two virCommandSetUmask to one] Signed-off-by: Daniel P. Berrangé <[email protected]> --- src/storage/storage_util.c | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-)
Reviewed-by: Ján Tomko <[email protected]> Jano
signature.asc
Description: PGP signature
