storage: create images with a private umask during qemu-img create/convert
On the local (non-NETFS) path virStorageBackendCreateExecCommand() ran
qemu-img with umask 0, so the destination image was created
world-readable (0644) and the full source disk was written into it
before libvirt tightened the mode with a later chmod(). This is the same
class as CVE-2025-13193; apply the same fix by setting a 0077 umask so
qemu-img creates the file private from the start.
Fixes: CVE-2026-63623 Reported-by: HE WEI(ギカク) <skyexpoc@gmail.com> Signed-off-by: HE WEI(ギカク) <skyexpoc@gmail.com>
[DB: merged the two virCommandSetUmask to one] Reviewed-by: Ján Tomko <jtomko@redhat.com> Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>