Red Hat Security Advisory: libvirt security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2026-18917 — libvirt: Integer overflow in NodeGetFreePages RPC handler leading to heap buffer overflow
🎯 Affected products170
- Red Hat Enterprise Linux AppStream E4S (v.9.2)
- libvirt-0:9.0.0-10.17.el9_2.aarch64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.2)
- libvirt-0:9.0.0-10.17.el9_2.ppc64le as a component of Red Hat Enterprise Linux AppStream E4S (v.9.2)
- libvirt-0:9.0.0-10.17.el9_2.s390x as a component of Red Hat Enterprise Linux AppStream E4S (v.9.2)
- libvirt-0:9.0.0-10.17.el9_2.src as a component of Red Hat Enterprise Linux AppStream E4S (v.9.2)
- libvirt-0:9.0.0-10.17.el9_2.x86_64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.2)
- libvirt-client-0:9.0.0-10.17.el9_2.aarch64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.2)
- libvirt-client-0:9.0.0-10.17.el9_2.ppc64le as a component of Red Hat Enterprise Linux AppStream E4S (v.9.2)
- libvirt-client-0:9.0.0-10.17.el9_2.s390x as a component of Red Hat Enterprise Linux AppStream E4S (v.9.2)
- libvirt-client-0:9.0.0-10.17.el9_2.x86_64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.2)
- libvirt-client-debuginfo-0:9.0.0-10.17.el9_2.aarch64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.2)
- libvirt-client-debuginfo-0:9.0.0-10.17.el9_2.ppc64le as a component of Red Hat Enterprise Linux AppStream E4S (v.9.2)
- libvirt-client-debuginfo-0:9.0.0-10.17.el9_2.s390x as a component of Red Hat Enterprise Linux AppStream E4S (v.9.2)
- libvirt-client-debuginfo-0:9.0.0-10.17.el9_2.x86_64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.2)
- libvirt-daemon-0:9.0.0-10.17.el9_2.aarch64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.2)
- libvirt-daemon-0:9.0.0-10.17.el9_2.ppc64le as a component of Red Hat Enterprise Linux AppStream E4S (v.9.2)
- libvirt-daemon-0:9.0.0-10.17.el9_2.s390x as a component of Red Hat Enterprise Linux AppStream E4S (v.9.2)
- libvirt-daemon-0:9.0.0-10.17.el9_2.x86_64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.2)
- libvirt-daemon-config-network-0:9.0.0-10.17.el9_2.aarch64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.2)
- libvirt-daemon-config-network-0:9.0.0-10.17.el9_2.ppc64le as a component of Red Hat Enterprise Linux AppStream E4S (v.9.2)
- libvirt-daemon-config-network-0:9.0.0-10.17.el9_2.s390x as a component of Red Hat Enterprise Linux AppStream E4S (v.9.2)
- libvirt-daemon-config-network-0:9.0.0-10.17.el9_2.x86_64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.2)
- libvirt-daemon-config-nwfilter-0:9.0.0-10.17.el9_2.aarch64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.2)
- libvirt-daemon-config-nwfilter-0:9.0.0-10.17.el9_2.ppc64le as a component of Red Hat Enterprise Linux AppStream E4S (v.9.2)
- libvirt-daemon-config-nwfilter-0:9.0.0-10.17.el9_2.s390x as a component of Red Hat Enterprise Linux AppStream E4S (v.9.2)
- libvirt-daemon-config-nwfilter-0:9.0.0-10.17.el9_2.x86_64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.2)
- libvirt-daemon-debuginfo-0:9.0.0-10.17.el9_2.aarch64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.2)
- libvirt-daemon-debuginfo-0:9.0.0-10.17.el9_2.ppc64le as a component of Red Hat Enterprise Linux AppStream E4S (v.9.2)
- libvirt-daemon-debuginfo-0:9.0.0-10.17.el9_2.s390x as a component of Red Hat Enterprise Linux AppStream E4S (v.9.2)
- libvirt-daemon-debuginfo-0:9.0.0-10.17.el9_2.x86_64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.2)
- +140 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Restrict access to the libvirt read-only Unix socket to limit which local users can reach the vulnerable RPC handler. In /etc/libvirt/libvirtd.conf, set unix_sock_ro_perms to "0770" (or "0700") and configure unix_sock_group to a group containing only trusted users. Alternatively, enable polkit authentication for the read-only socket by setting auth_unix_ro = "polkit", which requires callers to be authorized before any RPC dispatch occurs. After changing the configuration, restart the libvirtd service. Note: restricting socket access may prevent unprivileged monitoring tools or read-only management clients from connecting.