Red Hat Security Advisory: libvirt security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2026-18917 — libvirt: Integer overflow in NodeGetFreePages RPC handler leading to heap buffer overflow
🎯 Affected products200
- Red Hat Enterprise Linux AppStream E4S (v.9.4)
- libvirt-0:10.0.0-6.24.el9_4.aarch64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- libvirt-0:10.0.0-6.24.el9_4.ppc64le as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- libvirt-0:10.0.0-6.24.el9_4.s390x as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- libvirt-0:10.0.0-6.24.el9_4.src as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- libvirt-0:10.0.0-6.24.el9_4.x86_64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- libvirt-client-0:10.0.0-6.24.el9_4.aarch64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- libvirt-client-0:10.0.0-6.24.el9_4.ppc64le as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- libvirt-client-0:10.0.0-6.24.el9_4.s390x as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- libvirt-client-0:10.0.0-6.24.el9_4.x86_64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- libvirt-client-debuginfo-0:10.0.0-6.24.el9_4.aarch64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- libvirt-client-debuginfo-0:10.0.0-6.24.el9_4.ppc64le as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- libvirt-client-debuginfo-0:10.0.0-6.24.el9_4.s390x as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- libvirt-client-debuginfo-0:10.0.0-6.24.el9_4.x86_64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- libvirt-client-qemu-0:10.0.0-6.24.el9_4.aarch64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- libvirt-client-qemu-0:10.0.0-6.24.el9_4.s390x as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- libvirt-client-qemu-0:10.0.0-6.24.el9_4.x86_64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- libvirt-daemon-0:10.0.0-6.24.el9_4.aarch64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- libvirt-daemon-0:10.0.0-6.24.el9_4.ppc64le as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- libvirt-daemon-0:10.0.0-6.24.el9_4.s390x as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- libvirt-daemon-0:10.0.0-6.24.el9_4.x86_64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- libvirt-daemon-common-0:10.0.0-6.24.el9_4.aarch64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- libvirt-daemon-common-0:10.0.0-6.24.el9_4.ppc64le as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- libvirt-daemon-common-0:10.0.0-6.24.el9_4.s390x as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- libvirt-daemon-common-0:10.0.0-6.24.el9_4.x86_64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- libvirt-daemon-common-debuginfo-0:10.0.0-6.24.el9_4.aarch64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- libvirt-daemon-common-debuginfo-0:10.0.0-6.24.el9_4.ppc64le as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- libvirt-daemon-common-debuginfo-0:10.0.0-6.24.el9_4.s390x as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- libvirt-daemon-common-debuginfo-0:10.0.0-6.24.el9_4.x86_64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- libvirt-daemon-config-network-0:10.0.0-6.24.el9_4.aarch64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- +170 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Restrict access to the libvirt read-only Unix socket to limit which local users can reach the vulnerable RPC handler. In /etc/libvirt/libvirtd.conf, set unix_sock_ro_perms to "0770" (or "0700") and configure unix_sock_group to a group containing only trusted users. Alternatively, enable polkit authentication for the read-only socket by setting auth_unix_ro = "polkit", which requires callers to be authorized before any RPC dispatch occurs. After changing the configuration, restart the libvirtd service. Note: restricting socket access may prevent unprivileged monitoring tools or read-only management clients from connecting.