<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T19:12:16.967161+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:74424</id>
    <title>ALSA-2026:74424 — Important: libvirt security, bug fix, and enhancement update</title>
    <updated>2026-10-05T19:12:17.274171+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: libvirt, AlmaLinux:9: libvirt-client, AlmaLinux:9: libvirt-client-qemu, AlmaLinux:9: libvirt-daemon, AlmaLinux:9: libvirt-daemon-common, AlmaLinux:9: libvirt-daemon-config-network, AlmaLinux:9: libvirt-daemon-config-nwfilter, AlmaLinux:9: libvirt-daemon-driver-interface, AlmaLinux:9: libvirt-daemon-driver-network, AlmaLinux:9: libvirt-daemon-driver-nodedev and 22 more</p>
<p>The libvirt library contains a C API for managing and interacting with the virtualization capabilities of Linux and other operating systems. In addition, libvirt provides tools for remote management of virtualized systems.</p>
<p>Security Fix(es):</p>
<p>* libvirt: swtpm privilege escalation via symlink following (CVE-2026-63622)
  * libvirt: Integer overflow in NodeGetFreePages RPC handler leading to heap buffer overflow (CVE-2026-18917)</p>
<p>Bug Fix(es) and Enhancement(s):</p>
<p>* Live migration fails when virtio-vga becomes available, video device switches from virtio-gpu-pci to virtio-vga on target [almalinux-9.8.z] (JIRA:AlmaLinux-186018)
  * libvirt-guests does not work together with virtlockd on shutdown [almalinux-9.8.z] (JIRA:AlmaLinux-224986)
  * Expose guest-get-devices in libvirt-api [almalinux-9.8.z] (JIRA:AlmaLinux-243306)
  * allow hyperv pvpanic "device" to process Windows crash dump [almalinux-9.8.z] (JIRA:AlmaLinux-242549)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:74424"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-18917</id>
    <title>BELL-CVE-2026-18917</title>
    <updated>2026-10-05T19:12:17.274300+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: libvirt, Alpaquita:25: libvirt, Alpaquita:stream: libvirt</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-18917"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-382094</id>
    <title>EUVD-2026-382094</title>
    <updated>2026-10-05T19:12:17.274326+00:00</updated>
    <content>EUVD-2026-382094</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-382094"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-18917</id>
    <title>fkie_cve-2026-18917</title>
    <updated>2026-10-05T19:12:17.274340+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in libvirt. An unprivileged local user could exploit an integer overflow vulnerability in the NodeGetFreePages RPC handler. This flaw allows crafted values to bypass a size check, leading to an undersized memory buffer. Subsequently, real NUMA node data can overwrite this buffer. This heap buffer overflow can corrupt the root libvirt daemon's memory, potentially leading to a denial of service or local privilege escalation.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-18917"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-6jq9-9f7w-h7mc</id>
    <title>GHSA-6jq9-9f7w-h7mc</title>
    <updated>2026-10-05T19:12:17.274365+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in libvirt. An unprivileged local user could exploit an integer overflow vulnerability in the NodeGetFreePages RPC handler. This flaw allows crafted values to bypass a size check, leading to an undersized memory buffer. Subsequently, real NUMA node data can overwrite this buffer. This heap buffer overflow can corrupt the root libvirt daemon's memory, potentially leading to a denial of service or local privilege escalation.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-6jq9-9f7w-h7mc"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-18917</id>
    <title>msrc_CVE-2026-18917 — Libvirt: integer overflow in nodegetfreepages rpc handler leading to heap buffer overflow</title>
    <updated>2026-10-05T19:12:17.274382+00:00</updated>
    <content>msrc_CVE-2026-18917</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-18917"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-3632</id>
    <title>OESA-2026-3632 — libvirt security update</title>
    <updated>2026-10-05T19:12:17.274400+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP4: libvirt</p>
<p>Libvirt is a C toolkit to interact with the virtualization capabilities of recent versions of Linux (and other OSes). The main package includes the libvirtd server exporting the virtualization support.

Security Fix(es):</p>
<p>A flaw was found in libvirt. An unprivileged local user could exploit an integer overflow vulnerability in the NodeGetFreePages RPC handler. This flaw allows crafted values to bypass a size check, leading to an undersized memory buffer. Subsequently, real NUMA node data can overwrite this buffer. This heap buffer overflow can corrupt the root libvirt daemon&amp;apos;s memory, potentially leading to a denial of service or local privilege escalation.(CVE-2026-18917)</p>
<p>An injection vulnerability was found in libvirt&amp;apos;s virtual network driver. The network XML parser does not strip newline characters from DNS TXT record value attributes and SRV record domain/target attributes. These values are written verbatim into the dnsmasq configuration file generated by the network driver, allowing a user with permission to define virtual networks to inject arbitrary dnsmasq configuration directives such as dhcp-script, leading to arbitrary command execution as root.(CVE-2026-61477)</p>
<p>A flaw was found in libvirt. A local attacker, specifically a process running as the confined `swtpm` user, could exploit a symlink-following vulnerability in the `virFileChownFiles()` function. By planting a symbolic link within the `swtpm` state directory, the attacker could trick the root-l…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-3632"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11622-1</id>
    <title>openSUSE-SU-2026:11622-1 — libvirt-12.6.0-2.1 on GA media</title>
    <updated>2026-10-05T19:12:17.274437+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libvirt-12.6.0-2.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11622-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:68509</id>
    <title>RHSA-2026:68509 — Red Hat Security Advisory: libvirt security update</title>
    <updated>2026-10-05T19:12:17.274457+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libvirt: Integer overflow in NodeGetFreePages RPC handler leading to heap buffer overflow</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:68509"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:74424</id>
    <title>RLSA-2026:74424 — Important: libvirt security, bug fix, and enhancement update</title>
    <updated>2026-10-05T19:12:17.274475+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:9: libvirt</p>
<p>The libvirt library contains a C API for managing and interacting with the virtualization capabilities of Linux and other operating systems. In addition, libvirt provides tools for remote management of virtualized systems.</p>
<p>Security Fix(es):</p>
<p>* libvirt: swtpm privilege escalation via symlink following (CVE-2026-63622)</p>
<p>* libvirt: Integer overflow in NodeGetFreePages RPC handler leading to heap buffer overflow (CVE-2026-18917)</p>
<p>Bug Fix(es) and Enhancement(s):</p>
<p>* Live migration fails when virtio-vga becomes available, video device switches from virtio-gpu-pci to virtio-vga on target [rhel-9.8.z] (JIRA:Rocky Linux-186018)</p>
<p>* libvirt-guests does not work together with virtlockd on shutdown [rhel-9.8.z] (JIRA:Rocky Linux-224986)</p>
<p>* Expose guest-get-devices in libvirt-api [rhel-9.8.z] (JIRA:Rocky Linux-243306)</p>
<p>* allow hyperv pvpanic "device" to process Windows crash dump [rhel-9.8.z] (JIRA:Rocky Linux-242549)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:74424"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:23445-1</id>
    <title>SUSE-SU-2026:23445-1 — Security update for libvirt</title>
    <updated>2026-10-05T19:12:17.274506+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for libvirt</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:23445-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-18917</id>
    <title>UBUNTU-CVE-2026-18917</title>
    <updated>2026-10-05T19:12:17.274525+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: libvirt, Ubuntu:Pro:16.04:LTS: libvirt, Ubuntu:Pro:18.04:LTS: libvirt, Ubuntu:Pro:20.04:LTS: libvirt, Ubuntu:22.04:LTS: libvirt, Ubuntu:24.04:LTS: libvirt, Ubuntu:26.04:LTS: libvirt, Ubuntu:26.04:LTS: libvirt-hwe</p>
<p>A flaw was found in libvirt. An unprivileged local user could exploit an integer overflow vulnerability in the NodeGetFreePages RPC handler. This flaw allows crafted values to bypass a size check, leading to an undersized memory buffer. Subsequently, real NUMA node data can overwrite this buffer. This heap buffer overflow can corrupt the root libvirt daemon's memory, potentially leading to a denial of service or local privilege escalation.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-18917"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2954</id>
    <title>WID-SEC-W-2026-2954 — libvirt: Schwachstelle ermöglicht Privilegieneskalation und DoS</title>
    <updated>2026-10-05T19:12:17.274558+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann eine Schwachstelle in libvirt ausnutzen, um einen Denial-of-Service-Zustand zu verursachen oder Berechtigungen zu erweitern.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2954"/>
  </entry>
</feed>
