Logo
vulnerabilityCVE-2025-12748
Name
CVE-2025-12748
Source
NVD ( link)Debian ( link)
Description
A flaw was discovered in libvirt in the XML file processing. More specifically, the parsing of user provided XML files was performed before the ACL checks. A malicious user with limited permissions could exploit this flaw by submitting a specially crafted XML file, causing libvirt to allocate too much memory on the host. The excessive memory consumption could lead to a libvirt process crash on the host, resulting in a denial-of-service condition.
Published Date
Updated Date
Workaround
-
Advisories

Analysis#


Affected Component
Analysis
libvirt
Exploitable

Vulnerability Ratings#


5.5
CVSSv31
NaN
other

Others affected component#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
7.10.0
Exploitable