CVE-2019-3831: Critical severity ovirt vdsm vulnerability

Published Feb 14, 2019
·
Updated

A vulnerability was discovered in vdsm, version 4.19 through 4.30.3 and 4.30.5 through 4.30.8. The systemdrun function exposed to the vdsm system user could be abused to execute arbitrary commands as root.

Other sources

vdsm v4.19 through v4.30.3 and v4.30.5 through v4.30.8 exposed a systemdrun() function to the vdsm system user, which could be abused to run arbitrary commands as root. This breaks the defense-in-depth of having a non-root vdsm system account. While not exploitable by attackers under normal circumstances, this flaw could lead to a compromise of services running under the vdsm account being escalated to a full root compromise.

Upstream fix:

https://gerrit.ovirt.org/#/c/97659/

Originally introduced by:

commit e56541ccb372e106eeb4fc3f7afc575f8dd32de2 Author: Francesco Romani <fromani> Date: Fri Apr 22 10:15:54 2016 +0200

supervdsm: expose systemd utilities

Removed by:

commit f85f0527f1421618714e89eee03ee2f0400a65ae Author: Francesco Romani <fromani> Date: Thu Nov 22 13:44:25 2018 +0100

supervdsm: systemd: remove support

Re-introduced by:

commit daf5b3c3aaa3796b8f9be22fe2059f6f6152a3ce Author: Nir Soffer <nsoffer> Date: Sun Dec 9 16:53:28 2018 +0200

supervdsm: Add back systemd support

Red Hat

Affected Software

4 affected componentsFixes available
redhat/vdsm<4.30.9
4.30.9
Ovirt vdsm>=4.19<=4.30.3
Ovirt vdsm>=4.30.5<=4.30.8
redhat Gluster Storage=3.0

Event History

Mar 25, 2019
CVE Published
via MITRE·05:12 PM
Data Sourced
via MITRE·05:12 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:29 PM
RemedyDescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is CVE-2019-3831?

CVE-2019-3831 is a vulnerability discovered in vdsm that allows arbitrary command execution as root.

2

How severe is CVE-2019-3831?

CVE-2019-3831 has a severity rating of 6.7 (critical).

3

Which versions of vdsm are affected by CVE-2019-3831?

vdsm versions 4.19 through 4.30.3 and 4.30.5 through 4.30.8 are affected by CVE-2019-3831.

4

How can I fix CVE-2019-3831?

To fix CVE-2019-3831, update vdsm to version 4.30.9.

5

Where can I find more information about CVE-2019-3831?

You can find more information about CVE-2019-3831 at the following links: [link1](https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3831), [link2](https://gerrit.ovirt.org/#/c/97659/), [link3](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1677109).

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203