CVE-2026-18917: Libvirt: integer overflow in nodegetfreepages rpc handler leading to heap buffer overflow

Published Aug 20, 2026
·
Updated

A flaw was found in libvirt. An unprivileged local user could exploit an integer overflow vulnerability in the NodeGetFreePages RPC handler. This flaw allows crafted values to bypass a size check, leading to an undersized memory buffer. Subsequently, real NUMA node data can overwrite this buffer. This heap buffer overflow can corrupt the root libvirt daemon's memory, potentially leading to a denial of service or local privilege escalation.

Other sources

An integer overflow vulnerability was found in libvirt's NodeGetFreePages RPC handler in src/remote/remotedaemondispatch.c. The dispatcher computes a 32-bit product (pageslen cellCount) for both validation and memory allocation. While pageslen is XDR-capped at 1024, cellCount remains unbounded. The multiplication truncates modulo 2^32, allowing crafted values to bypass the guard check. The undersized buffer is then overwritten with real NUMA node data. The RPC call requires only connect:read ACL (lowest permission tier) and is accessible via the world-readable Unix socket (mode 0666) with no authentication for VIRCONNECTRO clients. An unprivileged local user could exploit this to corrupt the root libvirt daemon's heap, leading to denial of service or potentially local privilege escalation.

— Red Hat

Libvirt: integer overflow in nodegetfreepages rpc handler leading to heap buffer overflow

— Microsoft

Affected Software

3 affected componentsFixes available
libvirt
Microsoft azl3 libvirt 11.9.0-1<11.9.0-1
11.9.0-1
debian/libvirt<=9.0.0-4+deb12u2
11.3.0-3+deb13u312.7.0-1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 11.9.0-1
  2. Upgrade

    Upgrade debian/libvirt to a version that resolves this vulnerability.

    Fixed in 11.3.0-3+deb13u3Fixed in 12.7.0-1

Event History

Aug 20, 2026
Data Sourced
via Red Hat·09:04 AM
DescriptionSeverityAffected Software
CVE Published
via MITRE·09:54 AM
Data Sourced
via MITRE·09:54 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 AM
DescriptionSeverityWeakness
Aug 25, 2026
Data Sourced
via Microsoft·08:06 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·08:06 AM
DescriptionSeverity
Sep 28, 2026
Data Sourced
via Ubuntu·01:36 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Launchpad·01:37 PM
Description
Data Sourced
via Debian·01:37 PM
DescriptionAffected Software

Frequently Asked Questions

1

Who is realistically exposed to exploitation?

Systems running the root libvirt daemon are exposed if an unprivileged local user can issue requests to the NodeGetFreePages RPC handler. The attack is local and requires low privileges; no user interaction is required.

2

What does an attacker need to do to trigger the flaw?

An attacker needs to provide crafted values to the NodeGetFreePages RPC handler that cause an integer overflow and bypass its size check. Real NUMA node data can then overwrite the resulting undersized heap buffer.

3

What is the likely impact after successful exploitation?

The heap buffer overflow can corrupt memory in the root libvirt daemon. This may cause denial of service or enable local privilege escalation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203