CVE-2019-3886
Moderate
CVE-2019-3886
An incorrect permissions check was discovered in libvirt 4.8.0 and above. The readonly permission was allowed to invoke APIs depending on the guest agent, which could lead to potentially disclosing unintended information or denial of service by causing libvirt to block.
Exploit probability
1.1%
Published
April 4, 2019
Required by
Not available
Last source change
July 8, 2026
02 / AFFECTED SOFTWARE
Affected packages
18 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Open Source Vulnerabilities
CVE-2019-3886
View original source
An incorrect permissions check was discovered in libvirt 4.8.0 and above. The readonly permission was allowed to invoke APIs depending on the guest agent, which could lead to potentially disclosing unintended information or denial of service by causing libvirt to block.
05 / REFERENCES
Further evidence
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00105.html
- http://www.securityfocus.com/bid/107777
- https://access.redhat.com/errata/RHBA-2019:3723
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3886
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CYMNKXAUBZCFBBPFH64FJPH5EJH4GSU2/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R5DHYIFECZ7BMVXK4EP4FDFZXK7I5MZH/
- https://usn.ubuntu.com/4021-1/