libvirt-11.10.0-19.el9

- remote: Fix integer overflow in RPC handler for virNodeGetFreePages (CVE-2026-18917) (CVE-2026-18917, RHEL-245281)

Resolves: RHEL-245281
This commit is contained in:
Jiri Denemark 2026-08-31 16:00:14 +02:00
parent 0f2ee777b8
commit 42b4a1b138
2 changed files with 73 additions and 1 deletions

View File

@ -0,0 +1,68 @@
From 996eeabc0953d349b68cd29ea77fa1d7f55859f9 Mon Sep 17 00:00:00 2001
Message-ID: <996eeabc0953d349b68cd29ea77fa1d7f55859f9.1788184814.git.jdenemar@redhat.com>
From: Peter Krempa <pkrempa@redhat.com>
Date: Wed, 12 Aug 2026 16:51:58 +0200
Subject: [PATCH] remote: Fix integer overflow in RPC handler for
virNodeGetFreePages (CVE-2026-18917)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
CVE-2026-18917
The RPC handler 'remoteDispatchNodeGetFreePages' multiplies the 'npages'
argument with the 'cellcount' argument passed to 'virNodeGetFreePages',
both of which are declared as 'unsigned int' to both do an RPC limit
check against the 'REMOTE_NODE_MAX_CELLS' constant and then to allocate
the memory to hold the result from the actual hypervisor driver.
Since both the values are 'unsigned int' the product is also unsigned
int so big enough numbers can overflow, both passing the check and also
allocating not enough memory for the result. The hypervisor driver
assumes that the passed buffer is large enough and overwrites memory.
When this happens the the hypervisor daemon crashes.
This can be triggered e.g. by passing 1023 and 4198405 as values which
multiply to 1019 after wrapping to 32 bit unsigned value.
Use the VIR_INT_MULTIPLY_OVERFLOW macro in the check to avoid the issue
the same way as we do for other APIs doing multiplication of arguments
to determine amount of required memory.
Fixes: 34f2d0319d2098c77c8cc27d8350616029125a2b (v1.2.5-164-g34f2d0319d)
Closes: https://gitlab.com/libvirt/libvirt/-/work_items/903
Signed-off-by: Peter Krempa <pkrempa@redhat.com>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
(cherry picked from commit 5a62cbf2907d4590283597b46da9c0f41e7b4d4f)
https://redhat.atlassian.net/browse/RHEL-245281
---
src/remote/remote_daemon_dispatch.c | 9 +++++----
1 file changed, 5 insertions(+), 4 deletions(-)
diff --git a/src/remote/remote_daemon_dispatch.c b/src/remote/remote_daemon_dispatch.c
index 7e74ff063f..33b95f05a4 100644
--- a/src/remote/remote_daemon_dispatch.c
+++ b/src/remote/remote_daemon_dispatch.c
@@ -6658,13 +6658,14 @@ remoteDispatchNodeGetFreePages(virNetServer *server G_GNUC_UNUSED,
if (!conn)
goto cleanup;
- if (args->pages.pages_len * args->cellCount > REMOTE_NODE_MAX_CELLS) {
- virReportError(VIR_ERR_INTERNAL_ERROR, "%s",
- _("the result won't fit into REMOTE_NODE_MAX_CELLS"));
+ if (VIR_INT_MULTIPLY_OVERFLOW(args->pages.pages_len, args->cellCount) ||
+ args->pages.pages_len * args->cellCount > REMOTE_NODE_MAX_CELLS) {
+ virReportError(VIR_ERR_INTERNAL_ERROR,
+ _("npages * cellcount > REMOTE_NODE_MAX_CELLS (%1$u)"),
+ REMOTE_NODE_MAX_CELLS);
goto cleanup;
}
- /* Allocate return buffer. */
ret->counts.counts_val = g_new0(uint64_t,
args->pages.pages_len * args->cellCount);
--
2.55.0

View File

@ -294,7 +294,7 @@
Summary: Library providing a simple virtualization API
Name: libvirt
Version: 11.10.0
Release: 18%{?dist}%{?extra_release}
Release: 19%{?dist}%{?extra_release}
License: GPL-2.0-or-later AND LGPL-2.1-only AND LGPL-2.1-or-later AND OFL-1.1
URL: https://libvirt.org/
@ -464,6 +464,7 @@ Patch159: libvirt-qemu_agent-Introduce-guest-get-devices.patch
Patch160: libvirt-qemuagenttest-Introduce-GetGuestDeviceInfo-test-case.patch
Patch161: libvirt-qemu-Implement-device-info-for-virDomainGetGuestInfo-API.patch
Patch162: libvirt-virsh-Add-support-for-VIR_DOMAIN_GUEST_INFO_DEVICES.patch
Patch163: libvirt-remote-Fix-integer-overflow-in-RPC-handler-for-virNodeGetFreePages-CVE-2026-18917.patch
Requires: libvirt-daemon = %{version}-%{release}
@ -2855,6 +2856,9 @@ exit 0
%endif
%changelog
* Mon Aug 31 2026 Jiri Denemark <jdenemar@redhat.com> - 11.10.0-19
- remote: Fix integer overflow in RPC handler for virNodeGetFreePages (CVE-2026-18917) (CVE-2026-18917, RHEL-245281)
* Wed Aug 19 2026 Jiri Denemark <jdenemar@redhat.com> - 11.10.0-18
- qemu: Always assume support for 'QEMU_CAPS_SET_ACTION' (RHEL-242546)
- qemu: Remove unused 'qemuProcessRebootAllowed' (RHEL-242546)