Red Hat Security Advisory: libvirt security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2026-18917 — libvirt: Integer overflow in NodeGetFreePages RPC handler leading to heap buffer overflow
🎯 Affected products200
- Red Hat CodeReady Linux Builder EUS (v.9.6)
- Red Hat Enterprise Linux AppStream EUS (v.9.6)
- libvirt-0:10.10.0-7.19.el9_6.aarch64 as a component of Red Hat Enterprise Linux AppStream EUS (v.9.6)
- libvirt-0:10.10.0-7.19.el9_6.ppc64le as a component of Red Hat Enterprise Linux AppStream EUS (v.9.6)
- libvirt-0:10.10.0-7.19.el9_6.s390x as a component of Red Hat Enterprise Linux AppStream EUS (v.9.6)
- libvirt-0:10.10.0-7.19.el9_6.src as a component of Red Hat Enterprise Linux AppStream EUS (v.9.6)
- libvirt-0:10.10.0-7.19.el9_6.x86_64 as a component of Red Hat Enterprise Linux AppStream EUS (v.9.6)
- libvirt-client-0:10.10.0-7.19.el9_6.aarch64 as a component of Red Hat Enterprise Linux AppStream EUS (v.9.6)
- libvirt-client-0:10.10.0-7.19.el9_6.ppc64le as a component of Red Hat Enterprise Linux AppStream EUS (v.9.6)
- libvirt-client-0:10.10.0-7.19.el9_6.s390x as a component of Red Hat Enterprise Linux AppStream EUS (v.9.6)
- libvirt-client-0:10.10.0-7.19.el9_6.x86_64 as a component of Red Hat Enterprise Linux AppStream EUS (v.9.6)
- libvirt-client-debuginfo-0:10.10.0-7.19.el9_6.aarch64 as a component of Red Hat CodeReady Linux Builder EUS (v.9.6)
- libvirt-client-debuginfo-0:10.10.0-7.19.el9_6.aarch64 as a component of Red Hat Enterprise Linux AppStream EUS (v.9.6)
- libvirt-client-debuginfo-0:10.10.0-7.19.el9_6.ppc64le as a component of Red Hat CodeReady Linux Builder EUS (v.9.6)
- libvirt-client-debuginfo-0:10.10.0-7.19.el9_6.ppc64le as a component of Red Hat Enterprise Linux AppStream EUS (v.9.6)
- libvirt-client-debuginfo-0:10.10.0-7.19.el9_6.s390x as a component of Red Hat CodeReady Linux Builder EUS (v.9.6)
- libvirt-client-debuginfo-0:10.10.0-7.19.el9_6.s390x as a component of Red Hat Enterprise Linux AppStream EUS (v.9.6)
- libvirt-client-debuginfo-0:10.10.0-7.19.el9_6.x86_64 as a component of Red Hat CodeReady Linux Builder EUS (v.9.6)
- libvirt-client-debuginfo-0:10.10.0-7.19.el9_6.x86_64 as a component of Red Hat Enterprise Linux AppStream EUS (v.9.6)
- libvirt-client-qemu-0:10.10.0-7.19.el9_6.aarch64 as a component of Red Hat Enterprise Linux AppStream EUS (v.9.6)
- libvirt-client-qemu-0:10.10.0-7.19.el9_6.s390x as a component of Red Hat Enterprise Linux AppStream EUS (v.9.6)
- libvirt-client-qemu-0:10.10.0-7.19.el9_6.x86_64 as a component of Red Hat Enterprise Linux AppStream EUS (v.9.6)
- libvirt-daemon-0:10.10.0-7.19.el9_6.aarch64 as a component of Red Hat Enterprise Linux AppStream EUS (v.9.6)
- libvirt-daemon-0:10.10.0-7.19.el9_6.ppc64le as a component of Red Hat Enterprise Linux AppStream EUS (v.9.6)
- libvirt-daemon-0:10.10.0-7.19.el9_6.s390x as a component of Red Hat Enterprise Linux AppStream EUS (v.9.6)
- libvirt-daemon-0:10.10.0-7.19.el9_6.x86_64 as a component of Red Hat Enterprise Linux AppStream EUS (v.9.6)
- libvirt-daemon-common-0:10.10.0-7.19.el9_6.aarch64 as a component of Red Hat Enterprise Linux AppStream EUS (v.9.6)
- libvirt-daemon-common-0:10.10.0-7.19.el9_6.ppc64le as a component of Red Hat Enterprise Linux AppStream EUS (v.9.6)
- libvirt-daemon-common-0:10.10.0-7.19.el9_6.s390x as a component of Red Hat Enterprise Linux AppStream EUS (v.9.6)
- libvirt-daemon-common-0:10.10.0-7.19.el9_6.x86_64 as a component of Red Hat Enterprise Linux AppStream EUS (v.9.6)
- +170 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Restrict access to the libvirt read-only Unix socket to limit which local users can reach the vulnerable RPC handler. In /etc/libvirt/libvirtd.conf, set unix_sock_ro_perms to "0770" (or "0700") and configure unix_sock_group to a group containing only trusted users. Alternatively, enable polkit authentication for the read-only socket by setting auth_unix_ro = "polkit", which requires callers to be authorized before any RPC dispatch occurs. After changing the configuration, restart the libvirtd service. Note: restricting socket access may prevent unprivileged monitoring tools or read-only management clients from connecting.