Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2026-18917

Опубликовано: 13 сент. 2026
Источник: msrc
CVSS3: 6.6
EPSS Низкий

Описание

Libvirt: integer overflow in nodegetfreepages rpc handler leading to heap buffer overflow

Обновления

ПродуктСтатьяОбновление
azl3 libvirt 11.9.0-1 on Azure Linux 3.0

Показывать по

EPSS

Процентиль: 7%
0.00169
Низкий

6.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 1 месяца назад

A flaw was found in libvirt. An unprivileged local user could exploit an integer overflow vulnerability in the NodeGetFreePages RPC handler. This flaw allows crafted values to bypass a size check, leading to an undersized memory buffer. Subsequently, real NUMA node data can overwrite this buffer. This heap buffer overflow can corrupt the root libvirt daemon's memory, potentially leading to a denial of service or local privilege escalation.

CVSS3: 7.8
redhat
около 1 года назад

A flaw was found in libvirt. An unprivileged local user could exploit an integer overflow vulnerability in the NodeGetFreePages RPC handler. This flaw allows crafted values to bypass a size check, leading to an undersized memory buffer. Subsequently, real NUMA node data can overwrite this buffer. This heap buffer overflow can corrupt the root libvirt daemon's memory, potentially leading to a denial of service or local privilege escalation.

CVSS3: 7.8
nvd
около 1 месяца назад

A flaw was found in libvirt. An unprivileged local user could exploit an integer overflow vulnerability in the NodeGetFreePages RPC handler. This flaw allows crafted values to bypass a size check, leading to an undersized memory buffer. Subsequently, real NUMA node data can overwrite this buffer. This heap buffer overflow can corrupt the root libvirt daemon's memory, potentially leading to a denial of service or local privilege escalation.

CVSS3: 7.8
debian
около 1 месяца назад

A flaw was found in libvirt. An unprivileged local user could exploit ...

CVSS3: 7.8
github
около 1 месяца назад

A flaw was found in libvirt. An unprivileged local user could exploit an integer overflow vulnerability in the NodeGetFreePages RPC handler. This flaw allows crafted values to bypass a size check, leading to an undersized memory buffer. Subsequently, real NUMA node data can overwrite this buffer. This heap buffer overflow can corrupt the root libvirt daemon's memory, potentially leading to a denial of service or local privilege escalation.

EPSS

Процентиль: 7%
0.00169
Низкий

6.6 Medium

CVSS3