CVE-2026-61478

NameCVE-2026-61478
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libvirt (PTS)bullseye7.0.0-3+deb11u3vulnerable
bullseye (security)7.0.0-3+deb11u4vulnerable
bookworm9.0.0-4+deb12u2vulnerable
trixie11.3.0-3+deb13u2vulnerable
forky12.5.0-1vulnerable
sid12.6.0-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libvirtsource(unstable)12.6.0-1

Notes

[trixie] - libvirt <no-dsa> (Minor issue)
Fixed by: https://gitlab.com/libvirt/libvirt/-/commit/68da70aae766c6271b8d3b466374d3cc7d1a8afb (v12.6.0-rc1)

Search for package or bug name: Reporting problems