RHSA-2026:68510HighCVSS 7.8

Red Hat Security Advisory: libvirt security update

Published
September 17, 2026
Last Modified
September 21, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2026-18917 — libvirt: Integer overflow in NodeGetFreePages RPC handler leading to heap buffer overflow

🎯 Affected products200

  • Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • Red Hat Enterprise Linux CodeReady Linux Builder EUS (v. 10.0)
  • libvirt-0:10.10.0-8.12.el10_0.aarch64 as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • libvirt-0:10.10.0-8.12.el10_0.ppc64le as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • libvirt-0:10.10.0-8.12.el10_0.s390x as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • libvirt-0:10.10.0-8.12.el10_0.src as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • libvirt-0:10.10.0-8.12.el10_0.x86_64 as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • libvirt-client-0:10.10.0-8.12.el10_0.aarch64 as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • libvirt-client-0:10.10.0-8.12.el10_0.ppc64le as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • libvirt-client-0:10.10.0-8.12.el10_0.s390x as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • libvirt-client-0:10.10.0-8.12.el10_0.x86_64 as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • libvirt-client-debuginfo-0:10.10.0-8.12.el10_0.aarch64 as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • libvirt-client-debuginfo-0:10.10.0-8.12.el10_0.aarch64 as a component of Red Hat Enterprise Linux CodeReady Linux Builder EUS (v. 10.0)
  • libvirt-client-debuginfo-0:10.10.0-8.12.el10_0.ppc64le as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • libvirt-client-debuginfo-0:10.10.0-8.12.el10_0.ppc64le as a component of Red Hat Enterprise Linux CodeReady Linux Builder EUS (v. 10.0)
  • libvirt-client-debuginfo-0:10.10.0-8.12.el10_0.s390x as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • libvirt-client-debuginfo-0:10.10.0-8.12.el10_0.s390x as a component of Red Hat Enterprise Linux CodeReady Linux Builder EUS (v. 10.0)
  • libvirt-client-debuginfo-0:10.10.0-8.12.el10_0.x86_64 as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • libvirt-client-debuginfo-0:10.10.0-8.12.el10_0.x86_64 as a component of Red Hat Enterprise Linux CodeReady Linux Builder EUS (v. 10.0)
  • libvirt-client-qemu-0:10.10.0-8.12.el10_0.aarch64 as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • libvirt-client-qemu-0:10.10.0-8.12.el10_0.s390x as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • libvirt-client-qemu-0:10.10.0-8.12.el10_0.x86_64 as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • libvirt-daemon-0:10.10.0-8.12.el10_0.aarch64 as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • libvirt-daemon-0:10.10.0-8.12.el10_0.ppc64le as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • libvirt-daemon-0:10.10.0-8.12.el10_0.s390x as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • libvirt-daemon-0:10.10.0-8.12.el10_0.x86_64 as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • libvirt-daemon-common-0:10.10.0-8.12.el10_0.aarch64 as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • libvirt-daemon-common-0:10.10.0-8.12.el10_0.ppc64le as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • libvirt-daemon-common-0:10.10.0-8.12.el10_0.s390x as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • libvirt-daemon-common-0:10.10.0-8.12.el10_0.x86_64 as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • +170 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Restrict access to the libvirt read-only Unix socket to limit which local users can reach the vulnerable RPC handler. In /etc/libvirt/libvirtd.conf, set unix_sock_ro_perms to "0770" (or "0700") and configure unix_sock_group to a group containing only trusted users. Alternatively, enable polkit authentication for the read-only socket by setting auth_unix_ro = "polkit", which requires callers to be authorized before any RPC dispatch occurs. After changing the configuration, restart the libvirtd service. Note: restricting socket access may prevent unprivileged monitoring tools or read-only management clients from connecting.

🔗 References (4)