CVE-2016-10746: High severity red hat libvirt-daemon-driver-storage-iscsi-direct vulnerability
libvirt-domain.c in libvirt before 1.3.1 supports virDomainGetTime API calls by guest agents with an RO connection, even though an RW connection was supposed to be required, a different vulnerability than CVE-2019-3886.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2016-10746?
CVE-2016-10746 is a vulnerability in libvirt that allows guest agents with an RO connection to make virDomainGetTime API calls, even when an RW connection is supposed to be required.
What is the severity of CVE-2016-10746?
CVE-2016-10746 is considered high severity with a severity value of 7.5.
Which software versions are affected by CVE-2016-10746?
Libvirt versions up to, but not including, 1.3.1 on Redhat and Debian Linux version 8.0 are affected by CVE-2016-10746.
How can I fix CVE-2016-10746?
To fix CVE-2016-10746, you should update your libvirt software to version 1.3.1 or later.
Where can I find more information about CVE-2016-10746?
You can find more information about CVE-2016-10746 at the following references: [Reference 1](https://github.com/libvirt/libvirt/commit/506e9d6c2d4baaf580d489fff0690c0ff2ff588f), [Reference 2](https://github.com/libvirt/libvirt/compare/11288f5...8fd6867), [Reference 3](https://lists.debian.org/debian-lts-announce/2019/04/msg00032.html).