Home / mailingsPDF  

[USN-8831-1] libvirt vulnerabilities

Posted on 28 September 2026
Ubuntu Security

==========================================================================Ubuntu Security Notice USN-8831-1
September 28, 2026

libvirt vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 26.04 LTS
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS

Summary:

Several security issues were fixed in libvirt.

Software Description:
- libvirt: Libvirt virtualization toolkit

Details:

It was discovered that libvirt had an integer overflow vulnerability in
the NodeGetFreePages RPC handler. A local attacker could possibly use
this issue to cause a denial of service or execute arbitrary code.
(CVE-2026-18917)

It was discovered that libvirt did not correctly handle symbolic links
when changing ownership of the TPM emulator log file. A local attacker
with access to the swtpm account could possibly use this issue to cause libvirt
to change the ownership of an arbitrary file. (CVE-2026-77159)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 26.04 LTS
libvirt-daemon 12.0.0-1ubuntu5.5
libvirt-daemon-system 12.0.0-1ubuntu5.5
libvirt0 12.0.0-1ubuntu5.5

Ubuntu 24.04 LTS
libvirt-daemon 10.0.0-2ubuntu8.19
libvirt-daemon-system 10.0.0-2ubuntu8.19
libvirt0 10.0.0-2ubuntu8.19

Ubuntu 22.04 LTS
libvirt-daemon 8.0.0-1ubuntu7.21
libvirt-daemon-system 8.0.0-1ubuntu7.21
libvirt0 8.0.0-1ubuntu7.21

After a standard system update you need to reboot your computer to make
all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-8831-1
CVE-2026-18917, CVE-2026-77159

Package Information:
https://launchpad.net/ubuntu/+source/libvirt/12.0.0-1ubuntu5.5
https://launchpad.net/ubuntu/+source/libvirt/10.0.0-2ubuntu8.19
https://launchpad.net/ubuntu/+source/libvirt/8.0.0-1ubuntu7.21

--===============4208245782245487636==Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature

 

TOP