cbcvebase.
CVE-2019-3840
published 2019-03-27

CVE-2019-3840: A NULL pointer dereference flaw was discovered in libvirt before version 5.0.0 in the way it gets interface information through the QEMU agent. An attacker in…

PriorityP429medium6.3CVSS 3.0
AVNACHPRLUINSCCNINAH
EPSS
1.51%
71.6th percentile
A NULL pointer dereference flaw was discovered in libvirt before version 5.0.0 in the way it gets interface information through the QEMU agent. An attacker in a guest VM can use this flaw to crash libvirtd and cause a denial of service.

Affected

9 ranges
VendorProductVersion rangeFixed in
debianlibvirt< libvirt 5.0.0-1 (bookworm)libvirt 5.0.0-1 (bookworm)
opensuseleap
opensuseleap
redhatlibvirt< 5.0.05.0.0
redhatlibvirt>= 0 < 5.0.0-15.0.0-1
redhatlibvirt>= 0 < 5.0.0-15.0.0-1
redhatlibvirt>= 0 < 5.0.0-15.0.0-1
redhatlibvirt>= 0 < 5.0.0-15.0.0-1
the_libvirt_projectlibvirt

CVSS provenance

nvdv3.06.3MEDIUMCVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:N/A:P
osv6.3MEDIUM
vendor_debian5.8MEDIUM
vendor_redhat5.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.