CVE-2019-3886
published 2019-04-04CVE-2019-3886: An incorrect permissions check was discovered in libvirt 4.8.0 and above. The readonly permission was allowed to invoke APIs depending on the guest agent…
PriorityP419medium5.4CVSS 3.1
AVAACLPRNUINSUCLINAL
EPSS
1.11%
62.2th percentile
An incorrect permissions check was discovered in libvirt 4.8.0 and above. The readonly permission was allowed to invoke APIs depending on the guest agent, which could lead to potentially disclosing unintended information or denial of service by causing libvirt to block.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | libvirt | < libvirt 5.0.0-2 (bookworm) | libvirt 5.0.0-2 (bookworm) |
| debian | libvirt | < libvirt 1.3.1-1 (bookworm) | libvirt 1.3.1-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cm1_libvirt_6.1.0-1_on_cbl_mariner_1.0 | — | — |
| opensuse | leap | — | — |
| redhat | libvirt | < 1.3.1 | 1.3.1 |
| redhat | libvirt | >= 0 < 5.0.0-2 | 5.0.0-2 |
| redhat | libvirt | >= 0 < 1.3.1-1 | 1.3.1-1 |
| redhat | libvirt | >= 0 < 5.0.0-2 | 5.0.0-2 |
| redhat | libvirt | >= 0 < 1.3.1-1 | 1.3.1-1 |
| redhat | libvirt | >= 0 < 5.0.0-2 | 5.0.0-2 |
| redhat | libvirt | >= 0 < 1.3.1-1 | 1.3.1-1 |
| redhat | libvirt | >= 0 < 5.0.0-2 | 5.0.0-2 |
| redhat | libvirt | >= 0 < 1.3.1-1 | 1.3.1-1 |
| redhat | libvirt | >= 4.8.0 < 5.3.0 | 5.3.0 |
| the_libvirt_project | libvirt | — | — |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
nvdv3.05.4MEDIUMCVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
nvdv2.04.8MEDIUMAV:A/AC:L/Au:N/C:P/I:N/A:P
osv7.5HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_msrc5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libvirt vulnerabilities
vendor_ubuntu·2019-06-19·CVSS 8.8
CVE-2019-10132 [HIGH] libvirt vulnerabilities
Title: libvirt vulnerabilities
Summary: Several security issues were fixed in libvirt.
Daniel P. Berrangé discovered that libvirt incorrectly handled socket
permissions. A local attacker could possibly use this issue to access
libvirt. (CVE-2019-10132)
It was discovered that libvirt incorrectly performed certain permission
checks. A remote attacker could possibly use this issue to access the
guest agent and cause a denial of service. This issue only affected Ubuntu
19.04. (CVE-2019-3886)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Red Hat
libvirt: libvirt-domain.c supports virDomainGetTime API calls with an RO connection instead of RW connection
vendor_redhat·2019-04-18·CVSS 7.5
CVE-2016-10746 [HIGH] CWE-648 libvirt: libvirt-domain.c supports virDomainGetTime API calls with an RO connection instead of RW connection
libvirt: libvirt-domain.c supports virDomainGetTime API calls with an RO connection instead of RW connection
libvirt-domain.c in libvirt before 1.3.1 supports virDomainGetTime API calls by guest agents with an RO connection, even though an RW connection was supposed to be required, a different vulnerability than CVE-2019-3886.
Package: libvirt (Red Hat Enterprise Linux 5) - Not affected
Package: libvirt (Red Hat Enterprise Linux 6) - Not affected
Package: libvirt (Red Hat Enterprise Linux 7) - Not affected
Package: libvirt (Red Hat Storage 3) - Not affected
Microsoft
An incorrect permissions check was discovered in libvirt 4.8.0 and above. The readonly permission was allowed to invoke APIs depending on the guest agent which could lead to potentially disclosing uni
vendor_msrc·2019-04-09·CVSS 5.4
CVE-2019-3886 [MEDIUM] CWE-862 An incorrect permissions check was discovered in libvirt 4.8.0 and above. The readonly permission was allowed to invoke APIs depending on the guest agent which could lead to potentially disclosing uni
An incorrect permissions check was discovered in libvirt 4.8.0 and above. The readonly permission was allowed to invoke APIs depending on the guest agent which could lead to potentially disclosing unintended information or denial of service by causing libvirt to block.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more informatio
Red Hat
libvirt: virsh domhostname command discloses guest hostname in readonly mode
vendor_redhat·2019-04-03·CVSS 5.4
CVE-2019-3886 [MEDIUM] CWE-862 libvirt: virsh domhostname command discloses guest hostname in readonly mode
libvirt: virsh domhostname command discloses guest hostname in readonly mode
An incorrect permissions check was discovered in libvirt 4.8.0 and above. The readonly permission was allowed to invoke APIs depending on the guest agent, which could lead to potentially disclosing unintended information or denial of service by causing libvirt to block.
An incorrect permissions check was discovered in libvirt 4.8.0 and above. The readonly permission was allowed to invoke APIs depending on the guest agent which could lead to potentially disclosing unintended information or denial of service by causing libvirt to block.
Package: libvirt (Red Hat Enterprise Linux 5) - Not affected
Package: libvirt (Red Hat Enterprise Linux 6) - Not affected
Package: libvirt (Red Hat Enterprise Linux 7) - Not aff
Debian
CVE-2019-3886: libvirt - An incorrect permissions check was discovered in libvirt 4.8.0 and above. The re...
vendor_debian·2019·CVSS 5.4
CVE-2019-3886 [MEDIUM] CVE-2019-3886: libvirt - An incorrect permissions check was discovered in libvirt 4.8.0 and above. The re...
An incorrect permissions check was discovered in libvirt 4.8.0 and above. The readonly permission was allowed to invoke APIs depending on the guest agent, which could lead to potentially disclosing unintended information or denial of service by causing libvirt to block.
Scope: local
bookworm: resolved (fixed in 5.0.0-2)
bullseye: resolved (fixed in 5.0.0-2)
forky: resolved (fixed in 5.0.0-2)
sid: resolved (fixed in 5.0.0-2)
trixie: resolved (fixed in 5.0.0-2)
Debian
CVE-2016-10746: libvirt - libvirt-domain.c in libvirt before 1.3.1 supports virDomainGetTime API calls by ...
vendor_debian·2016·CVSS 7.5
CVE-2016-10746 [HIGH] CVE-2016-10746: libvirt - libvirt-domain.c in libvirt before 1.3.1 supports virDomainGetTime API calls by ...
libvirt-domain.c in libvirt before 1.3.1 supports virDomainGetTime API calls by guest agents with an RO connection, even though an RW connection was supposed to be required, a different vulnerability than CVE-2019-3886.
Scope: local
bookworm: resolved (fixed in 1.3.1-1)
bullseye: resolved (fixed in 1.3.1-1)
forky: resolved (fixed in 1.3.1-1)
sid: resolved (fixed in 1.3.1-1)
trixie: resolved (fixed in 1.3.1-1)
GHSA
GHSA-66gq-pc92-3m6j: libvirt-domain
ghsa_unreviewed·2022-05-14·CVSS 5.4
CVE-2016-10746 [MEDIUM] GHSA-66gq-pc92-3m6j: libvirt-domain
libvirt-domain.c in libvirt before 1.3.1 supports virDomainGetTime API calls by guest agents with an RO connection, even though an RW connection was supposed to be required, a different vulnerability than CVE-2019-3886.
GHSA
GHSA-wxvx-hq9w-75x9: An incorrect permissions check was discovered in libvirt 4
ghsa_unreviewed·2022-05-13
CVE-2019-3886 [MEDIUM] CWE-862 GHSA-wxvx-hq9w-75x9: An incorrect permissions check was discovered in libvirt 4
An incorrect permissions check was discovered in libvirt 4.8.0 and above. The readonly permission was allowed to invoke APIs depending on the guest agent, which could lead to potentially disclosing unintended information or denial of service by causing libvirt to block.
OSV
CVE-2016-10746: libvirt-domain
osv·2019-04-18·CVSS 7.5
CVE-2016-10746 [HIGH] CVE-2016-10746: libvirt-domain
libvirt-domain.c in libvirt before 1.3.1 supports virDomainGetTime API calls by guest agents with an RO connection, even though an RW connection was supposed to be required, a different vulnerability than CVE-2019-3886.
OSV
CVE-2019-3886: An incorrect permissions check was discovered in libvirt 4
osv·2019-04-04·CVSS 5.4
CVE-2019-3886 [MEDIUM] CVE-2019-3886: An incorrect permissions check was discovered in libvirt 4
An incorrect permissions check was discovered in libvirt 4.8.0 and above. The readonly permission was allowed to invoke APIs depending on the guest agent, which could lead to potentially disclosing unintended information or denial of service by causing libvirt to block.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-15785 fontforge: buffer overflow in PrefsUI_LoadPrefs in prefs.c
bugzilla·2019-09-11·CVSS 9.8
CVE-2019-15785 [CRITICAL] CVE-2019-15785 fontforge: buffer overflow in PrefsUI_LoadPrefs in prefs.c
CVE-2019-15785 fontforge: buffer overflow in PrefsUI_LoadPrefs in prefs.c
A vulnerability was found in FontForge through 20190801 has a buffer overflow in PrefsUI_LoadPrefs in prefs.c.
Reference:
https://github.com/fontforge/fontforge/pull/3886
Discussion:
Created fontforge tracking bugs for this issue:
Affects: fedora-all [bug 1751050]
---
Please note there is no upstream release that includes the initial commit https://github.com/fontforge/fontforge/commit/626f751752875a0ddd74b9e217b6f4828713573c#diff-6e3cb09877f1c7fef21c68da73915a60 that added warn_script_unsaved to fontview.c and prefs.c files. Then how come this CVE got reported against Fedora 30?
---
Statement:
The versions of fontforge package shipped with Red Hat Enterprise Linux 5, 6, 7 and 8 are not affected by this iss
Bugzilla
CVE-2019-3886 libvirt: virsh domhostname command discloses guest hostname in readonly mode [fedora-rawhide]
bugzilla·2019-04-04·CVSS 5.4
CVE-2019-3886 [MEDIUM] CVE-2019-3886 libvirt: virsh domhostname command discloses guest hostname in readonly mode [fedora-rawhide]
CVE-2019-3886 libvirt: virsh domhostname command discloses guest hostname in readonly mode [fedora-rawhide]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-rawhide.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use t
Bugzilla
CVE-2019-3886 mingw-libvirt: libvirt: virsh domhostname command discloses guest hostname in readonly mode [fedora-rawhide]
bugzilla·2019-04-04·CVSS 5.4
CVE-2019-3886 [MEDIUM] CVE-2019-3886 mingw-libvirt: libvirt: virsh domhostname command discloses guest hostname in readonly mode [fedora-rawhide]
CVE-2019-3886 mingw-libvirt: libvirt: virsh domhostname command discloses guest hostname in readonly mode [fedora-rawhide]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-rawhide.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Di
Bugzilla
CVE-2019-3886 libvirt: virsh domhostname command discloses guest hostname in readonly mode
bugzilla·2019-04-01·CVSS 5.4
CVE-2019-3886 [MEDIUM] CVE-2019-3886 libvirt: virsh domhostname command discloses guest hostname in readonly mode
CVE-2019-3886 libvirt: virsh domhostname command discloses guest hostname in readonly mode
A vulnerability was found in libvirt versions >= 4.8.0. An information exposure allows to retrieve the guest hostname under readonly mode
References:
https://bugzilla.redhat.com/show_bug.cgi?id=1692619
Discussion:
NB, the flaw isn't the fact that the guest hostname is disclosed, but rather that the act of getting the hostname involves talking to the guest agent. The guest agent is untrusted and can block libvirt operations for a period of time, and so unprivileged users must not be allowed to run operations that talk to the guest agent.
---
Patches posted upstream at:
https://www.redhat.com/archives/libvir-list/2019-April/msg00339.html
NB part of the flaw was found to also affect the virDoma
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00105.htmlhttp://www.securityfocus.com/bid/107777https://access.redhat.com/errata/RHBA-2019:3723https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3886https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CYMNKXAUBZCFBBPFH64FJPH5EJH4GSU2/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R5DHYIFECZ7BMVXK4EP4FDFZXK7I5MZH/https://usn.ubuntu.com/4021-1/http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00105.htmlhttp://www.securityfocus.com/bid/107777https://access.redhat.com/errata/RHBA-2019:3723https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3886https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CYMNKXAUBZCFBBPFH64FJPH5EJH4GSU2/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R5DHYIFECZ7BMVXK4EP4FDFZXK7I5MZH/https://usn.ubuntu.com/4021-1/
2019-04-04
Published