Libguestfs is a virtualization library and toolkit for accessing virtual machine filesystems and disk images, deployed in Linux environments where it serves image inspection, manipulation, and backup workflows. The durable signal from its vulnerability profile centers on memory-safety issues characteristic of native C code, including buffer overflows and exposure of sensitive information. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Libguestfs over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-2211MEDIUM A vulnerability was found in libguestfs. This issue occurs while calculating the greatest possible number of matching keys in the get_keys() function. This flaw leads to a denial o | Jul 12, 2022 | 6.5 | 19 | NO | NO |
CVE-2013-2124MEDIUM Double free vulnerability in inspect-fs.c in LibguestFS 1.20.x before 1.20.7, 1.21.x, 1.22.0, and 1.23.0 allows remote attackers to cause a denial of service (crash) via empty gues | May 27, 2014 | 4.3 | 19 | NO | NO |
CVE-2013-4419MEDIUM The guestfish command in libguestfs 1.20.12, 1.22.7, and earlier, when using the --remote or --listen option, does not properly check the ownership of /tmp/.guestfish-$UID/ when cr | Nov 5, 2013 | 6.8 | 18 | NO | NO |
CVE-2010-3851MEDIUM libguestfs before 1.5.23, as used in virt-v2v, virt-inspector 1.5.3 and earlier, and possibly other products, when a raw-format disk image is used, allows local guest OS administra | Nov 4, 2010 | 4.7 | 18 | NO | NO |
virt-edit in libguestfs before 1.18.0 does not preserve the permissions from the original file and saves the new file with world-readable permissions when editing, which might allo | Jun 29, 2012 | 2.1 | 13 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Libguestfs.
Media articles that mention a CVE ID that affects a product developed by Libguestfs — matched by CVE ID, not by vendor name.