Red HatCVE-2026-18917
Red Hat Enterprise Linux 10: integer overflow
High7.8CVE-2026-18917 · Published Aug 20, 2026 · updated Sep 21, 2026
A flaw was found in libvirt. An unprivileged local user could exploit an integer overflow vulnerability in the NodeGetFreePages RPC handler. This flaw allows crafted values to bypass a size check, leading to an undersized memory buffer. Subsequently, real NUMA node data can overwrite this buffer. This heap buffer overflow can corrupt the root libvirt daemon's memory, potentially leading to a denial of service or local privilege escalation.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Red Hat Enterprise Linux 10 Product | all versions | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-190
- www.cve.org/CVERecord?id=CVE-2026-18917
- nvd.nist.gov/vuln/detail/CVE-2026-18917
- access.redhat.com/errata/RHSA-2026:68509
- access.redhat.com/errata/RHSA-2026:68510
- access.redhat.com/errata/RHSA-2026:68511
- access.redhat.com/errata/RHSA-2026:68513
- access.redhat.com/errata/RHSA-2026:68514
- access.redhat.com/errata/RHSA-2026:68594
- access.redhat.com/errata/RHSA-2026:69114
- access.redhat.com/errata/RHSA-2026:69131
- access.redhat.com/security/cve/CVE-2026-18917
- bugzilla.redhat.com/show_bug.cgi?id=2520161
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 20 | Red Hat multicloud-operators-subscription: information disclosure | High7.7 | No fix yet |
| Aug 20 | A flaw was found in the multicloud-operators-subscription component | Critical9.9 | No fix yet |
| Aug 20 | Red Hat Advanced Cluster Management for Kubernetes 2: information disclosure | Low2.5 | No fix yet |
| Aug 20 | Red Hat lighthouse: information disclosure | Medium5.4 | No fix yet |
| Aug 20 | Red Hat Lighthouse. A remote attacker: privilege escalation | Low3.7 | No fix yet |
| Aug 20 | A flaw was found in Kata Containers | High8.1 | No fix yet |