CVE-2019-3831: Critical severity ovirt vdsm vulnerability
A vulnerability was discovered in vdsm, version 4.19 through 4.30.3 and 4.30.5 through 4.30.8. The systemdrun function exposed to the vdsm system user could be abused to execute arbitrary commands as root.
Other sources
vdsm v4.19 through v4.30.3 and v4.30.5 through v4.30.8 exposed a systemdrun() function to the vdsm system user, which could be abused to run arbitrary commands as root. This breaks the defense-in-depth of having a non-root vdsm system account. While not exploitable by attackers under normal circumstances, this flaw could lead to a compromise of services running under the vdsm account being escalated to a full root compromise.
Upstream fix:
https://gerrit.ovirt.org/#/c/97659/
Originally introduced by:
commit e56541ccb372e106eeb4fc3f7afc575f8dd32de2 Author: Francesco Romani <fromani> Date: Fri Apr 22 10:15:54 2016 +0200
supervdsm: expose systemd utilities
Removed by:
commit f85f0527f1421618714e89eee03ee2f0400a65ae Author: Francesco Romani <fromani> Date: Thu Nov 22 13:44:25 2018 +0100
supervdsm: systemd: remove support
Re-introduced by:
commit daf5b3c3aaa3796b8f9be22fe2059f6f6152a3ce Author: Nir Soffer <nsoffer> Date: Sun Dec 9 16:53:28 2018 +0200
supervdsm: Add back systemd support
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-3831?
CVE-2019-3831 is a vulnerability discovered in vdsm that allows arbitrary command execution as root.
How severe is CVE-2019-3831?
CVE-2019-3831 has a severity rating of 6.7 (critical).
Which versions of vdsm are affected by CVE-2019-3831?
vdsm versions 4.19 through 4.30.3 and 4.30.5 through 4.30.8 are affected by CVE-2019-3831.
How can I fix CVE-2019-3831?
To fix CVE-2019-3831, update vdsm to version 4.30.9.
Where can I find more information about CVE-2019-3831?
You can find more information about CVE-2019-3831 at the following links: [link1](https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3831), [link2](https://gerrit.ovirt.org/#/c/97659/), [link3](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1677109).