CVE-2026-63622: Red Hat Enterprise Linux 10

High severity, CVSS 7.8. EPSS: 0.1% chance of exploitation in the next 30 days.

A flaw was found in libvirt. A local attacker, specifically a process running as the confined `swtpm` user, could exploit a symlink-following vulnerability in the `virFileChownFiles()` function. By planting a symbolic link within the `swtpm` state directory, the attacker could trick the root-level libvirt daemon into changing the ownership of an arbitrary file to the `swtpm` user. This allows for privilege escalation from the `swtpm` sandbox to root-level file ownership control.

Affected products

  • Red Hat Red Hat Enterprise Linux 10: before 0:11.10.0-12.9.el10_2 (fixed in 0:11.10.0-12.9.el10_2)
  • Red Hat Red Hat Enterprise Linux 10.0 Extended Update Support: before 0:10.10.0-8.11.el10_0 (fixed in 0:10.10.0-8.11.el10_0)
  • Red Hat Red Hat Enterprise Linux 6
  • Red Hat Red Hat Enterprise Linux 7 Extended Lifecycle Support: before 0:4.5.0-36.el7_9.7 (fixed in 0:4.5.0-36.el7_9.7)
  • Red Hat Red Hat Enterprise Linux 8
  • Red Hat Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support: before 8040020260916092751.522a0ee4 (fixed in 8040020260916092751.522a0ee4)
  • Red Hat Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On: before 8040020260916092751.522a0ee4 (fixed in 8040020260916092751.522a0ee4)
  • Red Hat Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support: before 8060020260910092451.ad008a3a (fixed in 8060020260910092451.ad008a3a)
  • Red Hat Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On: before 8060020260910092451.ad008a3a (fixed in 8060020260910092451.ad008a3a)
  • Red Hat Red Hat Enterprise Linux 8.8 Telecommunications Update Service: before 8080020260910092120.63b34585 (fixed in 8080020260910092120.63b34585)
  • Red Hat Red Hat Enterprise Linux 8.8 Update Services For SAP Solutions: before 8080020260910092120.63b34585 (fixed in 8080020260910092120.63b34585)
  • Red Hat Red Hat Enterprise Linux 9: before 0:11.10.0-12.7.el9_8 (fixed in 0:11.10.0-12.7.el9_8)
  • Red Hat Red Hat Enterprise Linux 9.2 Update Services For SAP Solutions: before 0:9.0.0-10.16.el9_2 (fixed in 0:9.0.0-10.16.el9_2)
  • Red Hat Red Hat Enterprise Linux 9.4 Update Services For SAP Solutions: before 0:10.0.0-6.23.el9_4 (fixed in 0:10.0.0-6.23.el9_4)
  • Red Hat Red Hat Enterprise Linux 9.6 Extended Update Support: before 0:10.10.0-7.18.el9_6 (fixed in 0:10.10.0-7.18.el9_6)
  • Red Hat Red Hat Enterprise Linux For NVIDIA 26

Published 2026-08-10. Last modified 2026-10-05.