Heap Buffer Overflow in Libvirt Affecting Red Hat
CVE-2026-18917

7.8HIGH

What is CVE-2026-18917?

A vulnerability exists in libvirt that enables an unprivileged local user to exploit an integer overflow in the NodeGetFreePages RPC handler. This flaw occurs when crafted values bypass the necessary size checks, resulting in an undersized memory buffer. Consequently, valid NUMA node data can overwrite this buffer, leading to a heap buffer overflow. This may corrupt the memory of the root libvirt daemon, potentially resulting in a denial of service or granting local privilege escalation.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.