CVE-2019-10166
published 2019-08-02CVE-2019-10166: It was discovered that libvirtd, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, would permit readonly clients to use the virDomainManagedSaveDefineXML()…
PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.47%
37.6th percentile
It was discovered that libvirtd, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, would permit readonly clients to use the virDomainManagedSaveDefineXML() API, which would permit them to modify managed save state files. If a managed save had already been created by a privileged user, a local attacker could modify this file such that libvirtd would execute an arbitrary program when the domain was resumed.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libvirt | < libvirt 5.0.0-4 (bookworm) | libvirt 5.0.0-4 (bookworm) |
| libvirt | libvirt | — | — |
| libvirt | libvirt | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | libvirt | >= 0 < 5.0.0-4 | 5.0.0-4 |
| redhat | libvirt | >= 0 < 5.0.0-4 | 5.0.0-4 |
| redhat | libvirt | >= 0 < 5.0.0-4 | 5.0.0-4 |
| redhat | libvirt | >= 0 < 5.0.0-4 | 5.0.0-4 |
| redhat | libvirt | >= 4.0.0 < 4.10.1 | 4.10.1 |
| redhat | libvirt | >= 5.0.0 < 5.4.1 | 5.4.1 |
| redhat | virtualization | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libvirt vulnerabilities
vendor_ubuntu·2019-07-08
CVE-2019-10161 libvirt vulnerabilities
Title: libvirt vulnerabilities
Summary: Several security issues were fixed in libvirt.
Matthias Gerstner and Ján Tomko discovered that libvirt incorrectly handled
certain API calls. An attacker could possibly use this issue to check for
arbitrary files, or execute arbitrary binaries. In the default
installation, attackers would be isolated by the libvirt AppArmor profile.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Red Hat
libvirt: virDomainManagedSaveDefineXML API exposed to readonly clients
vendor_redhat·2019-06-20·CVSS 7.8
CVE-2019-10166 [HIGH] CWE-284 libvirt: virDomainManagedSaveDefineXML API exposed to readonly clients
libvirt: virDomainManagedSaveDefineXML API exposed to readonly clients
It was discovered that libvirtd, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, would permit readonly clients to use the virDomainManagedSaveDefineXML() API, which would permit them to modify managed save state files. If a managed save had already been created by a privileged user, a local attacker could modify this file such that libvirtd would execute an arbitrary program when the domain was resumed.
It was discovered that libvirtd would permit readonly clients to use the virDomainManagedSaveDefineXML() API, which would permit them to modify managed save state files. If a managed save had already been created by a privileged user, a local attacker could modify this file such that libvirtd would execute an arbi
Debian
CVE-2019-10166: libvirt - It was discovered that libvirtd, versions 4.x.x before 4.10.1 and 5.x.x before 5...
vendor_debian·2019·CVSS 7.8
CVE-2019-10166 [HIGH] CVE-2019-10166: libvirt - It was discovered that libvirtd, versions 4.x.x before 4.10.1 and 5.x.x before 5...
It was discovered that libvirtd, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, would permit readonly clients to use the virDomainManagedSaveDefineXML() API, which would permit them to modify managed save state files. If a managed save had already been created by a privileged user, a local attacker could modify this file such that libvirtd would execute an arbitrary program when the domain was resumed.
Scope: local
bookworm: resolved (fixed in 5.0.0-4)
bullseye: resolved (fixed in 5.0.0-4)
forky: resolved (fixed in 5.0.0-4)
sid: resolved (fixed in 5.0.0-4)
trixie: resolved (fixed in 5.0.0-4)
GHSA
GHSA-g9cg-gvh5-48hm: It was discovered that libvirtd, versions 4
ghsa_unreviewed·2022-05-24
CVE-2019-10166 [HIGH] GHSA-g9cg-gvh5-48hm: It was discovered that libvirtd, versions 4
It was discovered that libvirtd, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, would permit readonly clients to use the virDomainManagedSaveDefineXML() API, which would permit them to modify managed save state files. If a managed save had already been created by a privileged user, a local attacker could modify this file such that libvirtd would execute an arbitrary program when the domain was resumed.
OSV
CVE-2019-10166: It was discovered that libvirtd, versions 4
osv·2019-08-02·CVSS 7.8
CVE-2019-10166 [HIGH] CVE-2019-10166: It was discovered that libvirtd, versions 4
It was discovered that libvirtd, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, would permit readonly clients to use the virDomainManagedSaveDefineXML() API, which would permit them to modify managed save state files. If a managed save had already been created by a privileged user, a local attacker could modify this file such that libvirtd would execute an arbitrary program when the domain was resumed.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-10166 mingw-libvirt: libvirt: virDomainManagedSaveDefineXML API exposed to readonly clients [fedora-all]
bugzilla·2019-06-20·CVSS 7.8
CVE-2019-10166 [HIGH] CVE-2019-10166 mingw-libvirt: libvirt: virDomainManagedSaveDefineXML API exposed to readonly clients [fedora-all]
CVE-2019-10166 mingw-libvirt: libvirt: virDomainManagedSaveDefineXML API exposed to readonly clients [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue
Bugzilla
CVE-2019-10166 libvirt: virDomainManagedSaveDefineXML API exposed to readonly clients [fedora-all]
bugzilla·2019-06-20·CVSS 7.8
CVE-2019-10166 [HIGH] CVE-2019-10166 libvirt: virDomainManagedSaveDefineXML API exposed to readonly clients [fedora-all]
CVE-2019-10166 libvirt: virDomainManagedSaveDefineXML API exposed to readonly clients [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multip
Bugzilla
CVE-2019-10166 libvirt: virDomainManagedSaveDefineXML API exposed to readonly clients
bugzilla·2019-06-13·CVSS 7.8
CVE-2019-10166 [HIGH] CVE-2019-10166 libvirt: virDomainManagedSaveDefineXML API exposed to readonly clients
CVE-2019-10166 libvirt: virDomainManagedSaveDefineXML API exposed to readonly clients
It was discovered that libvirtd would permit readonly clients to use the
virDomainManagedSaveDefineXML() API, which would permit them to modify
managed save state files. If a managed save had already been created by
a privileged user, a local attacker could modify this file such that
libvirtd would execute an arbitrary program when the domain was resumed.
This vulnerability was first present in libvirt v3.6.1.
Discussion:
Statement:
* This vulnerability requires access to the libvirt socket, normally in /var/run/libvirt/libvirt_sock_ro. Typically in hypervisor environments, local user accounts are not supported so no untrusted users should be able to access this socket.
* Red Hat Gluster Storage 3 is
https://access.redhat.com/libvirt-privesc-vulnerabilitieshttps://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10166https://security.gentoo.org/glsa/202003-18https://access.redhat.com/libvirt-privesc-vulnerabilitieshttps://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10166https://security.gentoo.org/glsa/202003-18
2019-08-02
Published