CVE-2019-10166: High severity red hat libvirt-daemon-driver-storage-iscsi-direct vulnerability
It was discovered that libvirtd would permit readonly clients to use the virDomainManagedSaveDefineXML() API, which would permit them to modify managed save state files. If a managed save had already been created by a privileged user, a local attacker could modify this file such that libvirtd would execute an arbitrary program when the domain was resumed.
This vulnerability was first present in libvirt v3.6.1.
Other sources
It was discovered that libvirtd, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, would permit readonly clients to use the virDomainManagedSaveDefineXML() API, which would permit them to modify managed save state files. If a managed save had already been created by a privileged user, a local attacker could modify this file such that libvirtd would execute an arbitrary program when the domain was resumed.
Affected Software
Remediation
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2019-10166.
What is the severity of CVE-2019-10166?
CVE-2019-10166 has a high severity rating.
What is the affected software?
The affected software is libvirtd versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1.
How can the vulnerability be fixed?
To fix the vulnerability, update libvirtd to version 4.10.1 or newer.
Where can I find more information about CVE-2019-10166?
You can find more information about CVE-2019-10166 at the following references: [1] [2] [3].