---
id: CVE-2026-18917
title: A flaw was found in libvirt
summary: >-
  A flaw was found in libvirt. An unprivileged local user could exploit an
  integer overflow vulnerability in the NodeGetFreePages RPC handler. This flaw
  allows crafted values to bypass a size check, leading to an undersized memory
  buffer. …
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-190
vendor: Red Hat
product: libvirt
affected:
  - libvirt (all versions)
  - libvirt (all versions)
  - 'virt:rhel (all versions)'
  - 'virt:rhel (all versions)'
  - 'virt:rhel (all versions)'
  - 'virt:rhel (all versions)'
  - 'virt:rhel (all versions)'
  - 'virt:rhel (all versions)'
  - libvirt (all versions)
  - libvirt (all versions)
  - libvirt (all versions)
  - libvirt (all versions)
  - libvirt
  - 'virt:rhel/libvirt (all versions)'
  - libvirt (all versions)
  - libvirt
patched:
  - enterprise_linux_appstream_eus_v_10_0
  - enterprise_linux_appstream_aus_v_8_6
  - enterprise_linux_appstream_eus_extension_v_8_6
  - enterprise_linux_appstream_e4s_v_8_8
  - enterprise_linux_appstream_tus_v_8_8
  - enterprise_linux_appstream_e4s_v_9_2
  - enterprise_linux_appstream_e4s_v_9_4
  - enterprise_linux_appstream_eus_v_9_6
  - enterprise_linux_codeready_linux_builder_eus_v_10_0
  - codeready_linux_builder_eus_v_9_6
published: '2026-08-20'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T06:17:01.053'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-18917'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2026:68509'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:68510'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:68511'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:68513'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:68514'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:68594'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:69114'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:69131'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2026-18917'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2520161'
    label: secalert@redhat.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-18917.json
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-18917'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-18917'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-08-20T15:33:25.231709Z'
epss: 0.00182
epssPercentile: 0.06836
ingestedAt: '2026-09-15T07:33:29.272Z'
---

## Overview

A flaw was found in libvirt. An unprivileged local user could exploit an integer overflow vulnerability in the NodeGetFreePages RPC handler. This flaw allows crafted values to bypass a size check, leading to an undersized memory buffer. Subsequently, real NUMA node data can overwrite this buffer. This heap buffer overflow can corrupt the root libvirt daemon's memory, potentially leading to a denial of service or local privilege escalation.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **Red Hat VEX** · Important · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux for NVIDIA 26 · no fix planned: Red Hat Enterprise Linux for NVIDIA 26, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9 · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-18917.json)
- **RHSA-2026:68510** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v. 10.0), Red Hat Enterprise Linux CodeReady Linux Builder EUS (v. 10.0) · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68510)
- **RHSA-2026:68594** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream AUS (v.8.6), Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.6) · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68594)
- **RHSA-2026:68513** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.8.8), Red Hat Enterprise Linux AppStream TUS (v.8.8) · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68513)
- **RHSA-2026:68514** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.9.2) · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68514)
- **RHSA-2026:68509** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.9.4) · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68509)
- **RHSA-2026:68511** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v.9.6), Red Hat CodeReady Linux Builder EUS (v.9.6) · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68511)
- **RHSA-2026:69114** · Red Hat · fixed in: Red Hat Enterprise Linux Server (v. 7 ELS), Red Hat Enterprise Linux Server Optional (v. 7 ELS) · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69114)
- **RHSA-2026:69131** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream AUS (v.8.4), Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.4) · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69131)
