SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-3886

The readonly permission was allowed to invoke APIs depending on the guest agent, which could lead to potentially disclosing unintended information or denial of service by causing libvirt to block.

MEDIUM 5.4EPSS 1.11%

Does this matter?

Lower severity and a low EPSS score (1.11%). Track it; it rarely justifies an emergency change on its own.

Description

An incorrect permissions check was discovered in libvirt 4.8.0 and above. The readonly permission was allowed to invoke APIs depending on the guest agent, which could lead to potentially disclosing unintended information or denial of service by causing libvirt to block.

CVSS 3.1
5.4 MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
EPSS
1.11% probability · 64th percentile
CISA KEV
Not listed
Weakness
CWE-862
Affected
redhat/libvirt · opensuse/leap · fedoraproject/fedora
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.