Heap Buffer Overflow in Libvirt Affecting Red Hat
CVE-2026-18917
Key Information:
- Vendor
Red Hat
- Status
- Vendor
- CVE Published:
- 20 August 2026
What is CVE-2026-18917?
A vulnerability exists in libvirt that enables an unprivileged local user to exploit an integer overflow in the NodeGetFreePages RPC handler. This flaw occurs when crafted values bypass the necessary size checks, resulting in an undersized memory buffer. Consequently, valid NUMA node data can overwrite this buffer, leading to a heap buffer overflow. This may corrupt the memory of the root libvirt daemon, potentially resulting in a denial of service or granting local privilege escalation.
Affected Version(s)
Red Hat Enterprise Linux 10.0 Extended Update Support 0:10.10.0-8.12.el10_0
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support 8060020260910092451.ad008a3a
Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On 8060020260910092451.ad008a3a