VDB
CVE-2026-18917
CVE-2026-18917
PUBLISHED
CVSS 7.8 HIGH
Reported by redhat · Published August 20, 2026
A flaw was found in libvirt. An unprivileged local user could exploit an integer overflow vulnerability in the NodeGetFreePages RPC handler. This flaw allows crafted values to bypass a size check, leading to an undersized memory buffer. Subsequently, real NUMA node data can overwrite this buffer. This heap buffer overflow can corrupt the root libvirt daemon's memory, potentially leading to a denial of service or local privilege escalation.
Risk Scores
CVSS 3.1
7.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | 0:11.10.0-12.9.el10_2 |
| Red Hat | Red Hat Enterprise Linux 10.0 Extended Update Support | 0:10.10.0-8.12.el10_0 |
| Red Hat | Red Hat Enterprise Linux 7 Extended Lifecycle Support | 0:4.5.0-36.el7_9.7 |
| Red Hat | Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | 8040020260916092751.522a0ee4 |
| Red Hat | Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | 8040020260916092751.522a0ee4 |
| Red Hat | Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | 8060020260910092451.ad008a3a |
| Red Hat | Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On | 8060020260910092451.ad008a3a |
| Red Hat | Red Hat Enterprise Linux 8.8 Telecommunications Update Service | 8080020260910092120.63b34585 |
| Red Hat | Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | 8080020260910092120.63b34585 |
| Red Hat | Red Hat Enterprise Linux 9 | 0:11.10.0-12.7.el9_8 |
| Red Hat | Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | 0:9.0.0-10.17.el9_2 |
| Red Hat | Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions | 0:10.0.0-6.24.el9_4 |
| Red Hat | Red Hat Enterprise Linux 9.6 Extended Update Support | 0:10.10.0-7.19.el9_6 |
| Red Hat | Red Hat Enterprise Linux 6 | |
| Red Hat | Red Hat Enterprise Linux 8 | |
| Red Hat | Red Hat Enterprise Linux for NVIDIA 26 | |
| Red Hat | Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | 8060020260910092451.ad008a3a, 8060020260910092451.ad008a3a, 8060020260910092451.ad008a3a |
| Red Hat | Red Hat Enterprise Linux 7 Extended Lifecycle Support | 0:4.5.0-36.el7_9.7, 0:4.5.0-36.el7_9.7, 0:4.5.0-36.el7_9.7 |
| Red Hat | Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | 0:9.0.0-10.17.el9_2, 0:9.0.0-10.17.el9_2, 0:9.0.0-10.17.el9_2 |
| Red Hat | Red Hat Enterprise Linux 10 | 0:11.10.0-12.9.el10_2 |
…and 13 more
Timeline
- Aug 20, 2026 CVE Published
- Aug 22, 2026 Coalition ESS Score
- Aug 24, 2026 EPSS Score
- Sep 2, 2026 Security Advisory
- Sep 9, 2026 EPSS Score
- Sep 16, 2026 EPSS Score
- Sep 17, 2026 EPSS Score
- Sep 21, 2026 EPSS Score
- Sep 21, 2026 Distribution Patch
- Sep 21, 2026 Security Advisory
- Sep 21, 2026 Distribution Patch
- Sep 21, 2026 Security Advisory
References
- RHSA-2026:68509 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:68510 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:68511 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:68513 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:68514 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:68594 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:69114 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:69131 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:74424 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:75583 vendor-advisoryx_refsource_REDHAT
- vdb-entryx_refsource_REDHAT
- RHBZ#2520161 issue-trackingx_refsource_REDHAT