I'm having the same problem on sid after upgrading today when libvirt* packages got upgraded from 4.1.0-2 to 4.2.0-1. 'virsh net-start default ' also failed so I think problem's probably with libvirt libraries.
syslog has messages like this: Apr 7 21:09:19 ws libvirtd[6210]: 2018-04-07 19:09:19.108+0000: 6230: info : libvirt version: 4.2.0, package: 1 (Guido Günther <a...@sigxcpu.org> Fri, 06 Apr 2018 12:33:30 +0200) Apr 7 21:09:19 ws libvirtd[6210]: 2018-04-07 19:09:19.108+0000: 6230: info : hostname: ws Apr 7 21:09:19 ws libvirtd[6210]: 2018-04-07 19:09:19.108+0000: 6230: error : virFirewallValidateBackend:193 : direct firewall backend requested, but /usr/sbin/iptables is not available: No such file or directory Apr 7 21:09:19 ws libvirtd[6210]: 2018-04-07 19:09:19.108+0000: 6230: error : virFirewallApply:918 : internal error: Failed to initialize a valid firewall backend Apr 7 21:09:19 ws libvirtd[6210]: 2018-04-07 19:09:19.108+0000: 6230: error : virFirewallApply:918 : internal error: Failed to initialize a valid firewall backend Apr 7 21:09:19 ws kernel: [ 130.013856] audit: type=1400 audit(1523128159.103:26): apparmor="DENIED" operation="signal" profile="/usr/sbin/libvirtd" pid=6210 comm="libvirtd" requested_mask="send" denied_mask="send" signal=hup peer="unconfined" Apr 7 21:09:19 ws libvirtd[6210]: 2018-04-07 19:09:19.147+0000: 6230: error : virFirewallApply:918 : internal error: Failed to initialize a valid firewall backend Symlinking iptables, installing dnsmasq and firewalld solved the issue for me for the moment.