A flaw was found in libvirt. An unprivileged local user could exploit an integer overflow vulnerability in the NodeGetFreePages RPC handler. This flaw allows crafted values to bypass a size check, leading to an undersized memory buffer. Subsequently, real NUMA node data can overwrite this buffer. This heap buffer overflow can corrupt the root libvirt daemon's memory, potentially leading to a denial of service or local privilege escalation.
Metrics
Affected Vendors & Products
References
History
Thu, 20 Aug 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in libvirt. An unprivileged local user could exploit an integer overflow vulnerability in the NodeGetFreePages RPC handler. This flaw allows crafted values to bypass a size check, leading to an undersized memory buffer. Subsequently, real NUMA node data can overwrite this buffer. This heap buffer overflow can corrupt the root libvirt daemon's memory, potentially leading to a denial of service or local privilege escalation. | |
| Title | Libvirt: integer overflow in nodegetfreepages rpc handler leading to heap buffer overflow | |
| First Time appeared |
Redhat
Redhat enterprise Linux Redhat enterprise Linux Nvidia |
|
| Weaknesses | CWE-190 | |
| CPEs | cpe:/a:redhat:enterprise_linux_nvidia: cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:6 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux Redhat enterprise Linux Nvidia |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-08-20T15:36:10.363Z
Reserved: 2026-08-05T07:41:23.966Z
Link: CVE-2026-18917
No data.
Status : Awaiting Analysis
Published: 2026-08-20T10:16:40.507
Modified: 2026-08-20T13:08:53.900
Link: CVE-2026-18917
No data.
OpenCVE Enrichment
No data.