This update for libvirt fixes the following issues:
Security fixes:
* CVE-2025-13193: Fixed umask for 'qemu-img' when creating external inactive
snapshots (bsc#1253703)
* CVE-2025-12748: Fixed check ACLs before parsing the whole domain XML
(bsc#1253278)
Other fixes:
* libvirt-supportconfig: Add support for supportconfig.rc (bsc#1251822)
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-375=1
* SUSE Linux Enterprise Micro for Rancher 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2026-375=1
* SUSE Linux Enterprise Micro 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2026-375=1
* SUSE Linux Enterprise Micro for Rancher 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2026-375=1
* SUSE Linux Enterprise Micro 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2026-375=1
* openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586)
* libvirt-daemon-8.0.0-150400.7.14.1
* libvirt-daemon-driver-storage-mpath-debuginfo-8.0.0-150400.7.14.1
* libvirt-lock-sanlock-debuginfo-8.0.0-150400.7.14.1
* libvirt-daemon-driver-storage-core-8.0.0-150400.7.14.1
* libvirt-daemon-driver-storage-mpath-8.0.0-150400.7.14.1
* libvirt-daemon-driver-storage-gluster-8.0.0-150400.7.14.1
* libvirt-daemon-lxc-8.0.0-150400.7.14.1
* libvirt-client-8.0.0-150400.7.14.1
* libvirt-devel-8.0.0-150400.7.14.1
* libvirt-daemon-driver-storage-logical-debuginfo-8.0.0-150400.7.14.1
* libvirt-daemon-driver-storage-disk-debuginfo-8.0.0-150400.7.14.1
* libvirt-daemon-driver-secret-8.0.0-150400.7.14.1
* libvirt-daemon-driver-nodedev-debuginfo-8.0.0-150400.7.14.1
* libvirt-daemon-driver-storage-iscsi-debuginfo-8.0.0-150400.7.14.1
* wireshark-plugin-libvirt-8.0.0-150400.7.14.1
* libvirt-daemon-driver-storage-iscsi-8.0.0-150400.7.14.1
* libvirt-daemon-driver-network-8.0.0-150400.7.14.1
*...
Read the Full Advisory* bsc#1251822
* bsc#1253278
* bsc#1253703
## References:
* https://www.suse.com/security/cve/CVE-2025-12748.html
* https://www.suse.com/security/cve/CVE-2025-13193.html
* https://bugzilla.suse.com/show_bug.cgi?id=1251822
* https://bugzilla.suse.com/show_bug.cgi?id=1253278
* https://bugzilla.suse.com/show_bug.cgi?id=1253703
Get the latest Linux and open source security news straight to your inbox.