CVE-2019-3886: Medium severity redhat libvirt vulnerability
A vulnerability was found in libvirt versions >= 4.8.0. An information exposure allows to retrieve the guest hostname under readonly mode
References: https://bugzilla.redhat.com/showbug.cgi?id=1692619
Other sources
An incorrect permissions check was discovered in libvirt 4.8.0 and above. The readonly permission was allowed to invoke APIs depending on the guest agent, which could lead to potentially disclosing unintended information or denial of service by causing libvirt to block.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-3886?
CVE-2019-3886 is a vulnerability in libvirt 4.8.0 and above that allows the readonly permission to invoke APIs, potentially leading to unintended information disclosure or denial of service.
What is the severity of CVE-2019-3886?
CVE-2019-3886 has a severity rating of 5.4 (medium).
Which software versions are affected by CVE-2019-3886?
Versions 4.8.0 to 5.3.0 of Redhat Libvirt, openSUSE Leap 42.3, Fedora 29, Fedora 30, and various versions of libvirt in Ubuntu and Debian are affected by CVE-2019-3886.
How do I fix CVE-2019-3886 in Redhat Libvirt?
To fix CVE-2019-3886 in Redhat Libvirt, update to version 5.4.0 or newer.
Where can I find more information about CVE-2019-3886?
You can find more information about CVE-2019-3886 in the following references: http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00105.html, http://www.securityfocus.com/bid/107777, and https://access.redhat.com/errata/RHBA-2019:3723