- Package:
- src:libvirt
- Source:
- src:libvirt
- Submitter:
- Salvatore Bonaccorso
- Date:
- 2026-09-02 21:55:02 UTC
- Severity:
- normal
- Tags:
Source: libvirt Version: 12.6.0-1 Severity: important Tags: security upstream Forwarded: https://gitlab.com/libvirt/libvirt/-/work_items/903 X-Debbugs-Cc: carnil@debian.org, Debian Security Team <team@security.debian.org> Control: found -1 11.3.0-3+deb13u2 Control: found -1 11.3.0-3 Control: found -1 1.2.6-1 Hi, The following vulnerability was published for libvirt. CVE-2026-18917[0]: | A flaw was found in libvirt. An unprivileged local user could | exploit an integer overflow vulnerability in the NodeGetFreePages | RPC handler. This flaw allows crafted values to bypass a size check, | leading to an undersized memory buffer. Subsequently, real NUMA node | data can overwrite this buffer. This heap buffer overflow can | corrupt the root libvirt daemon's memory, potentially leading to a | denial of service or local privilege escalation. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-18917 https://www.cve.org/CVERecord?id=CVE-2026-18917 [1] https://gitlab.com/libvirt/libvirt/-/work_items/903 Please adjust the affected versions in the BTS as needed. Regards, Salvatore
We believe that the bug you reported is fixed in the latest version of
libvirt, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1145069@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Andrea Bolognani <eof@kiyuko.org> (supplier of updated libvirt package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Tue, 01 Sep 2026 22:08:21 +0200
Source: libvirt
Architecture: source
Version: 12.7.0-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Libvirt Maintainers <pkg-libvirt-maintainers@lists.alioth.debian.org>
Changed-By: Andrea Bolognani <eof@kiyuko.org>
Closes: 1145069
Changes:
libvirt (12.7.0-1) unstable; urgency=medium
.
* [38da4c3] New upstream version 12.7.0
- Closes: #1145069 (CVE-2026-18917)
Checksums-Sha1:
692ea6f7ba81558bf91275b1af1a991773562462 7646 libvirt_12.7.0-1.dsc
ac682f740d6e54da9e92d48a5035198303e93fc0 10709104 libvirt_12.7.0.orig.tar.xz
3a93032d05c8a3009ae20ce53030f9fc69f112c5 833 libvirt_12.7.0.orig.tar.xz.asc
7cb8ad0ca154a405ffb0c7356ab44b66aa045841 97984 libvirt_12.7.0-1.debian.tar.xz
954c45ab4c1016c99a234b76fb1538a44e464e58 13469 libvirt_12.7.0-1_source.buildinfo
Checksums-Sha256:
4f9602b62fd68ad2b4638e2b4eda90ddb6f27a9dec7cd5ff8ae9d05e5ba6ebfe 7646 libvirt_12.7.0-1.dsc
7ec1a04e7e4f4069353d4daac117bbe869287f5b202695de61fe1b079efb6cb6 10709104 libvirt_12.7.0.orig.tar.xz
669dbd66861dab4efb41fa9ca894988f3cd76cd483e485edb0fb53583c0cd76c 833 libvirt_12.7.0.orig.tar.xz.asc
3c0d2ae85e150f761fd3f8a826bc86ea570d5f36a285b2c517070bba58f640fb 97984 libvirt_12.7.0-1.debian.tar.xz
e15e0044632ff4e3141d54f9652c48d53a4c6a0ee8fcd976260934783fa19d8e 13469 libvirt_12.7.0-1_source.buildinfo
Files:
ab441dbe78759df37273f0b07b47ccd2 7646 libs optional libvirt_12.7.0-1.dsc
39771fe501ecf73116d02bcc17dc4a58 10709104 libs optional libvirt_12.7.0.orig.tar.xz
2f78f505e70d1ed5e154d17545252d01 833 libs optional libvirt_12.7.0.orig.tar.xz.asc
a3c2024646e965c5f0570e9036e22eab 97984 libs optional libvirt_12.7.0-1.debian.tar.xz
bae2bc11bfb238ec41ffb9c8a219a18e 13469 libs optional libvirt_12.7.0-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQJDBAEBCgAtFiEEO48t9niVypx3EjLf954fxUKFg6wFAmqYk30PHGVvZkBraXl1
a28ub3JnAAoJEPeeH8VChYOsGYkQALg4zm5rStFUFngTom9LLTAhMlIRxu7xRR9L
IGHElP1xo9ynwTwqt1mVKWNfYtO9QLyBSnlUPmqpmjjPNWO7JwJKBRJuMJbwsXDU
/qETdAppsgevDA9/dVMvZ/M3GYahcXJtovFjAMC/pU4ip/74gdVrqZ33Oa0siouM
+3WzncEkGaNGPRZ0YeRC6YTYz6Vf+IyqCOTwIg4QdOPP5E3tUyuCNKBsOB7kyC1J
3VGRtyEL/2frE0EuTB6Y/REieLS41GKkUbQyTypjn0KVJJVTGw8cUasr7fCA5Qb8
P2PhCqs/dFybbwd3PCX4HNgoxnHXusg1UUvgFrfUxElyF5t+IeAGYTzTTsioVSAC
Pz5VuOjZ9O7EwiSxMrKGXljiJg5SgI6SIKNyBHT15IejOf+5IuU6SJ90mec6EWhI
vn5Pjot/NUbkgKqEEokwM3FScdp9KoTQqrq5vxIDIMMc/zIwrl8rV5eMv1ym60rv
EzG6fnOT5XpFJM4uEyg3zWqapxuSeIqwo4ZTFc6FSyEmIxwdCwwJuMxjwcnhMWDt
mOl0EyPZQbaYKYzhXSUjfknoh/Iov5bidSvd7UUMpHRSoKBs7Oc941kgeCCMLTBB
0ouavnVOOgzb/94NHBk0RrNv2ncLX+b4tJwv/S6ajfXT05W4NUGH9DytSoZHbHCO
XTXEud0c
=IsQ/
-----END PGP SIGNATURE-----