{"id":"AZL-101739","summary":"CVE-2026-77159 affecting package libvirt 11.9.0-1","details":"A symlink-following flaw was found in libvirt's qemuTPMEmulatorPrepareHost() function. The function uses a path-based chown() on the swtpm logfile without checking for symbolic links. A local attacker with access to the swtpm account can replace the logfile with a symlink, causing libvirtd (running as root) to transfer ownership of an arbitrary file to the swtpm user.","modified":"2026-09-18T05:37:08Z","published":"2026-09-11T11:16:54Z","upstream":["CVE-2026-77159"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-77159"}],"affected":[{"package":{"name":"libvirt","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/libvirt"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"11.9.0-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-101739.json"}}],"schema_version":"1.9.0"}