SUSE libvirt Vulnerabilities Prompt Urgent Security Updates

SUSE libvirt Vulnerabilities Prompt Urgent Security Updates

First seen 4 Sep 2026, 20:12 UTC Linuxsecurity 72.0

Article Content

Browse articles
ThreatCluster

SUSE has issued security advisories for multiple vulnerabilities in libvirt, affecting Linux systems. Notable vulnerabilities include CVE-2026-18917, an integer overflow leading to a heap buffer overflow, and CVE-2026-63622, which allows privilege escalation via symlink following. Other issues involve potential information disclosure and configuration injection risks. The vulnerabilities impact various libvirt functionalities, including RPC handlers and file permissions. The updates were released on September 2 and September 3, 2026, with CVE-2026-18917 rated at 7.8 and CVE-2026-63622 at 8.5 on the CVSS scale. Administrators are urged to apply patches immediately using SUSE's recommended methods. The vulnerabilities were published between August 7 and August 20, 2026, and are now considered critical for system security.

Key Points: • SUSE released critical updates for libvirt addressing multiple vulnerabilities. • CVE-2026-18917 and CVE-2026-63622 pose significant risks including buffer overflow and privilege escalation. • System administrators must apply patches immediately to mitigate these vulnerabilities.

Ask AI about this cluster

Timeline

2026-08-07
CVE-2026-61477 published
Vulnerability related to newline injection in network XML DNS fields disclosed.
Linuxsecurity
2026-08-10
CVE-2026-63622 and CVE-2026-63623 published
Two vulnerabilities disclosed involving privilege escalation and information disclosure.
Linuxsecurity
2026-08-20
CVE-2026-18917 published
Integer overflow vulnerability in RPC handler leading to heap buffer overflow disclosed.
Linuxsecurity
2026-09-02
SUSE advisory released for libvirt vulnerabilities
SUSE issued a security advisory detailing vulnerabilities and recommended patches.
Linuxsecurity
2026-09-03
Additional SUSE advisory released
A second advisory was published addressing further vulnerabilities in libvirt.
Linuxsecurity