CVE-2019-10132
published 2019-05-22CVE-2019-10132: A vulnerability was found in libvirt >= 4.1.0 in the virtlockd-admin.socket and virtlogd-admin.socket systemd units. A missing SocketMode configuration…
PriorityP349high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EPSS
1.41%
69.7th percentile
A vulnerability was found in libvirt >= 4.1.0 in the virtlockd-admin.socket and virtlogd-admin.socket systemd units. A missing SocketMode configuration parameter allows any user on the host to connect using virtlockd-admin-sock or virtlogd-admin-sock and perform administrative tasks against the virtlockd and virtlogd daemons.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libvirt | < libvirt 5.0.0-3 (bookworm) | libvirt 5.0.0-3 (bookworm) |
| libvirt | libvirt | — | — |
| redhat | libvirt | <= 4.1.0 | — |
| redhat | libvirt | >= 0 < 5.0.0-3 | 5.0.0-3 |
| redhat | libvirt | >= 0 < 5.0.0-3 | 5.0.0-3 |
| redhat | libvirt | >= 0 < 5.0.0-3 | 5.0.0-3 |
| redhat | libvirt | >= 0 < 5.0.0-3 | 5.0.0-3 |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
vendor_ubuntu8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libvirt vulnerabilities
vendor_ubuntu·2019-06-19·CVSS 8.8
CVE-2019-10132 [HIGH] libvirt vulnerabilities
Title: libvirt vulnerabilities
Summary: Several security issues were fixed in libvirt.
Daniel P. Berrangé discovered that libvirt incorrectly handled socket
permissions. A local attacker could possibly use this issue to access
libvirt. (CVE-2019-10132)
It was discovered that libvirt incorrectly performed certain permission
checks. A remote attacker could possibly use this issue to access the
guest agent and cause a denial of service. This issue only affected Ubuntu
19.04. (CVE-2019-3886)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Red Hat
libvirt: wrong permissions in systemd admin-sock due to missing SocketMode parameter
vendor_redhat·2019-05-21·CVSS 8.8
CVE-2019-10132 [HIGH] CWE-732 libvirt: wrong permissions in systemd admin-sock due to missing SocketMode parameter
libvirt: wrong permissions in systemd admin-sock due to missing SocketMode parameter
A vulnerability was found in libvirt >= 4.1.0 in the virtlockd-admin.socket and virtlogd-admin.socket systemd units. A missing SocketMode configuration parameter allows any user on the host to connect using virtlockd-admin-sock or virtlogd-admin-sock and perform administrative tasks against the virtlockd and virtlogd daemons.
A flaw was found in libvirt in version 4.1.0 and earlier. A missing SocketMode configuration parameter allows any user on the host to connect using virtlockd-admin-sock or virtlogd-admin-sock and perform administrative tasks against the virtlockd and virtlogd daemons. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Debian
CVE-2019-10132: libvirt - A vulnerability was found in libvirt >= 4.1.0 in the virtlockd-admin.socket and ...
vendor_debian·2019·CVSS 8.8
CVE-2019-10132 [HIGH] CVE-2019-10132: libvirt - A vulnerability was found in libvirt >= 4.1.0 in the virtlockd-admin.socket and ...
A vulnerability was found in libvirt >= 4.1.0 in the virtlockd-admin.socket and virtlogd-admin.socket systemd units. A missing SocketMode configuration parameter allows any user on the host to connect using virtlockd-admin-sock or virtlogd-admin-sock and perform administrative tasks against the virtlockd and virtlogd daemons.
Scope: local
bookworm: resolved (fixed in 5.0.0-3)
bullseye: resolved (fixed in 5.0.0-3)
forky: resolved (fixed in 5.0.0-3)
sid: resolved (fixed in 5.0.0-3)
trixie: resolved (fixed in 5.0.0-3)
GHSA
GHSA-gf34-qgv2-76mf: A vulnerability was found in libvirt >= 4
ghsa_unreviewed·2022-05-24
CVE-2019-10132 [HIGH] CWE-732 GHSA-gf34-qgv2-76mf: A vulnerability was found in libvirt >= 4
A vulnerability was found in libvirt >= 4.1.0 in the virtlockd-admin.socket and virtlogd-admin.socket systemd units. A missing SocketMode configuration parameter allows any user on the host to connect using virtlockd-admin-sock or virtlogd-admin-sock and perform administrative tasks against the virtlockd and virtlogd daemons.
OSV
CVE-2019-10132: A vulnerability was found in libvirt >= 4
osv·2019-05-22·CVSS 8.8
CVE-2019-10132 [HIGH] CVE-2019-10132: A vulnerability was found in libvirt >= 4
A vulnerability was found in libvirt >= 4.1.0 in the virtlockd-admin.socket and virtlogd-admin.socket systemd units. A missing SocketMode configuration parameter allows any user on the host to connect using virtlockd-admin-sock or virtlogd-admin-sock and perform administrative tasks against the virtlockd and virtlogd daemons.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-10132 libvirt: wrong permissions in systemd admin-sock due to missing SocketMode parameter [fedora-all]
bugzilla·2019-05-21·CVSS 8.8
CVE-2019-10132 [HIGH] CVE-2019-10132 libvirt: wrong permissions in systemd admin-sock due to missing SocketMode parameter [fedora-all]
CVE-2019-10132 libvirt: wrong permissions in systemd admin-sock due to missing SocketMode parameter [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue
Bugzilla
CVE-2019-10132 mingw-libvirt: libvirt: wrong permissions in systemd admin-sock due to missing SocketMode parameter [fedora-all]
bugzilla·2019-05-21·CVSS 8.8
CVE-2019-10132 [HIGH] CVE-2019-10132 mingw-libvirt: libvirt: wrong permissions in systemd admin-sock due to missing SocketMode parameter [fedora-all]
CVE-2019-10132 mingw-libvirt: libvirt: wrong permissions in systemd admin-sock due to missing SocketMode parameter [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NO
Bugzilla
CVE-2019-10132 libvirt: wrong permissions in systemd admin-sock due to missing SocketMode parameter
bugzilla·2019-05-03·CVSS 8.8
CVE-2019-10132 [HIGH] CVE-2019-10132 libvirt: wrong permissions in systemd admin-sock due to missing SocketMode parameter
CVE-2019-10132 libvirt: wrong permissions in systemd admin-sock due to missing SocketMode parameter
A vulnerability was found in libvirt >= 4.1.0 in the virtlockd-admin.socket and virtlogd-admin.socket systemd units. A missing SocketMode configuration parameter allows any user on the host to connect using virtlockd-admin-sock or virtlogd-admin-sock and perform administrative tasks against the virtlockd and virtlogd daemons.
Discussion:
Created attachment 1564991
admin: reject clients unless their UID matches the current UID
---
Created attachment 1564992
locking: restrict sockets to mode 0600
---
Created attachment 1564993
logging: restrict sockets to mode 0600
---
The three patches above, provided by Daniel Berrange, address the issue in multiple layers: the first adds client ver
https://access.redhat.com/errata/RHSA-2019:1264https://access.redhat.com/errata/RHSA-2019:1268https://access.redhat.com/errata/RHSA-2019:1455https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10132https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5RANC4LWZQRVJGJHVWCU6R4CCXQMDD4L/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CYMNKXAUBZCFBBPFH64FJPH5EJH4GSU2/https://security.libvirt.org/2019/0003.htmlhttps://usn.ubuntu.com/4021-1/https://access.redhat.com/errata/RHSA-2019:1264https://access.redhat.com/errata/RHSA-2019:1268https://access.redhat.com/errata/RHSA-2019:1455https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10132https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5RANC4LWZQRVJGJHVWCU6R4CCXQMDD4L/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CYMNKXAUBZCFBBPFH64FJPH5EJH4GSU2/https://security.libvirt.org/2019/0003.htmlhttps://usn.ubuntu.com/4021-1/
2019-05-22
Published