CVE-2025-13193: Libvirt: information disclosure via world-readable vm snapshots
A flaw was found in libvirt. External inactive snapshots for shut-down VMs are incorrectly created as world-readable, making it possible for unprivileged users to inspect the guest OS contents. This results in an information disclosure vulnerability.
Security readout for executives and security teams
Plain-English summary
Libvirt can create external inactive snapshots for shut-down virtual machines with permissions that allow any local user to read them. Those snapshots may contain guest operating system data. The main business risk is unauthorized disclosure of VM contents from virtualization hosts, especially where multiple users or teams have local access.
Executive priority
Treat as a targeted confidentiality risk on virtualization infrastructure. Prioritize shared or multi-user hosts and environments handling sensitive VM data. It is not currently supported as actively exploited, but VM snapshot exposure can create meaningful data leakage if local access controls are weak.
Technical view
CVE-2025-13193 is a libvirt CWE-276 permissions flaw. External inactive snapshots for shut-down VMs are incorrectly created world-readable. CVSS 3.1 is 5.5, local attack vector, low complexity, low privileges, no user interaction, high confidentiality impact, no integrity or availability impact.
Likely exposure
Exposure is most relevant on Red Hat Enterprise Linux hosts running affected libvirt packages, especially RHEL 8, 9, and 10 per the source bundle. RHEL 6 and 7 status is listed as unknown. Systems without local unprivileged users or without affected snapshot workflows have reduced practical exposure.
Exploitation context
The cited CVSS vector requires local access with low privileges. No KEV listing or cited source indicates active exploitation. An attacker would need access to the virtualization host and readable snapshot files to inspect guest contents. The issue is confidentiality-focused, not remote code execution.
Researcher notes
Evidence identifies incorrect world-readable permissions for external inactive snapshots of shut-down VMs. Affected status is explicit for RHEL 8, 9, and 10, unknown for RHEL 6 and 7. Public sources provided do not name a specific fixed version, patch advisory, or observed exploitation.
Mitigation direction
Check Red Hat guidance and package advisories for fixed libvirt updates.
Prioritize virtualization hosts with local unprivileged user access.
Restrict local shell access on libvirt hosts where possible.
Avoid external inactive snapshots of shut-down VMs until remediated, if feasible.
Review and tighten snapshot file permissions using approved administrative controls.
Validation and detection
Inventory RHEL hosts running libvirt, especially RHEL 8, 9, and 10.
Identify external inactive snapshots for shut-down VMs.
Verify snapshot files are not readable by unprivileged local users.
Confirm package status against Red Hat CVE guidance.
Document any RHEL 6 or 7 exposure as unresolved pending vendor status.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · low confidence lookup
CWE-276: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
CWE-276 · source CWE mapping
Incorrect Default Permissions
Incorrect Default Permissions represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.