CVE-2026-18917

NameCVE-2026-18917
DescriptionA flaw was found in libvirt. An unprivileged local user could exploit an integer overflow vulnerability in the NodeGetFreePages RPC handler. This flaw allows crafted values to bypass a size check, leading to an undersized memory buffer. Subsequently, real NUMA node data can overwrite this buffer. This heap buffer overflow can corrupt the root libvirt daemon's memory, potentially leading to a denial of service or local privilege escalation.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1145069

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libvirt (PTS)bookworm9.0.0-4+deb12u2vulnerable
trixie11.3.0-3+deb13u2vulnerable
forky12.6.0-1vulnerable
sid12.7.0-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libvirtsource(unstable)12.7.0-11145069

Notes

[trixie] - libvirt <no-dsa> (Minor issue)
[bookworm] - libvirt <postponed> (Minor issue)
https://gitlab.com/libvirt/libvirt/-/work_items/903
Introduced with: https://gitlab.com/libvirt/libvirt/-/commit/34f2d0319d2098c77c8cc27d8350616029125a2b (v1.2.6-rc1)
Fixed by: https://gitlab.com/libvirt/libvirt/-/commit/5a62cbf2907d4590283597b46da9c0f41e7b4d4f (v12.7.0-rc1)

Search for package or bug name: Reporting problems