OESA-2026-3635
Dashboard / Vulnerabilities / OESA-2026-3635
OESA-2026-3635
Summary: libvirt security update
Details: Libvirt is a C toolkit to interact with the virtualization capabilities of recent versions of Linux (and other OSes). The main package includes the libvirtd server exporting the virtualization support. Security Fix(es): A flaw was found in libvirt. An unprivileged local user could exploit an integer overflow vulnerability in the NodeGetFreePages RPC handler. This flaw allows crafted values to bypass a size check, leading to an undersized memory buffer. Subsequently, real NUMA node data can overwrite this buffer. This heap buffer overflow can corrupt the root libvirt daemon's memory, potentially leading to a denial of service or local privilege escalation.(CVE-2026-18917) An injection vulnerability was found in libvirt's virtual network driver. The network XML parser does not strip newline characters from DNS TXT record value attributes and SRV record domain/target attributes. These values are written verbatim into the dnsmasq configuration file generated by the network driver, allowing a user with permission to define virtual networks to inject arbitrary dnsmasq configuration directives such as dhcp-script, leading to arbitrary command execution as root.(CVE-2026-61477) A flaw was found in libvirt. A local attacker, specifically a process running as the confined `swtpm` user, could exploit a symlink-following vulnerability in the `virFileChownFiles()` function. By planting a symbolic link within the `swtpm` state directory, the attacker could trick the root-level libvirt daemon into changing the ownership of an arbitrary file to the `swtpm` user. This allows for privilege escalation from the `swtpm` sandbox to root-level file ownership control.(CVE-2026-63622)
References: https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3635, https://nvd.nist.gov/vuln/detail/CVE-2026-18917, https://nvd.nist.gov/vuln/detail/CVE-2026-61477, https://nvd.nist.gov/vuln/detail/CVE-2026-63622
Affected packages
Package
Name: libvirt
Purl: pkg:rpm/openEuler/libvirt&distro=openEuler-24.03-LTS-SP3
Affected ranges
Type: ECOSYSTEM
Events:
