CVE-2018-6764: High severity redhat libvirt vulnerability
Last updated 25 August 2025
Other sources
libvirtlxc resolves a host name after the guest filesystem is mounted but before the init from it is executed. That in turn causes glibc to load libnssdns.so and it ends up being loaded from the guest tree, making it possible for the guest to inject executable code before the host filesystem is umounted and file handles closed. That has potential security implications.
— Red Hat
util/virlog.c in libvirt does not properly determine the hostname on LXC container startup, which allows local guest OS users to bypass an intended container protection mechanism and execute arbitrary commands via a crafted NSS module.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/libvirtto a version that resolves this vulnerability.Fixed in 7.0.0-3+deb11u3Fixed in 9.0.0-4+deb12u2Fixed in 11.3.0-3+deb13u2Fixed in 12.0.0-1
Event History
Frequently Asked Questions
What is CVE-2018-6764?
CVE-2018-6764 is a vulnerability in libvirt that allows local guest OS users to bypass container protection and execute arbitrary commands.
How do I know if I am affected by CVE-2018-6764?
If you are using libvirt version 5.0.0-4+deb10u1, 7.0.0-3+deb11u2, 9.0.0-4, 9.8.0-2, 1.3.1-1ubuntu10.19, 3.6.0-1ubuntu6.3, or older, you may be affected by CVE-2018-6764.
What is the severity of CVE-2018-6764?
CVE-2018-6764 has a severity rating of 7.8 (High).
How can I fix CVE-2018-6764?
To fix CVE-2018-6764, update libvirt to version 5.0.0-4+deb10u1, 7.0.0-3+deb11u2, 9.0.0-4, 9.8.0-2, 1.3.1-1ubuntu10.19, 3.6.0-1ubuntu6.3, or a newer version.
Are there any references available for CVE-2018-6764?
Yes, you can find references for CVE-2018-6764 at the following URLs: https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1542815, https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1542814, https://access.redhat.com/security/cve/CVE-2018-6764