First published: Wed Jun 19 2019(Updated: )
Daniel P. Berrangé discovered that libvirt incorrectly handled socket permissions. A local attacker could possibly use this issue to access libvirt. (CVE-2019-10132) It was discovered that libvirt incorrectly performed certain permission checks. A remote attacker could possibly use this issue to access the guest agent and cause a denial of service. This issue only affected Ubuntu 19.04. (CVE-2019-3886)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/libvirt0 | <5.0.0-1ubuntu2.3 | 5.0.0-1ubuntu2.3 |
=19.04 | ||
All of | ||
ubuntu/libvirt-daemon | <5.0.0-1ubuntu2.3 | 5.0.0-1ubuntu2.3 |
=19.04 | ||
All of | ||
ubuntu/libvirt-clients | <5.0.0-1ubuntu2.3 | 5.0.0-1ubuntu2.3 |
=19.04 | ||
All of | ||
ubuntu/libvirt0 | <4.6.0-2ubuntu3.7 | 4.6.0-2ubuntu3.7 |
=18.10 | ||
All of | ||
ubuntu/libvirt-daemon | <4.6.0-2ubuntu3.7 | 4.6.0-2ubuntu3.7 |
=18.10 | ||
All of | ||
ubuntu/libvirt-clients | <4.6.0-2ubuntu3.7 | 4.6.0-2ubuntu3.7 |
=18.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
USN-4021-1 is a security vulnerability in libvirt, a virtualization management library, which could allow local attackers to access libvirt.
USN-4021-1 affects Ubuntu 19.04 if the libvirt software version is 5.0.0-1ubuntu2.3 or earlier.
USN-4021-1 affects Ubuntu 18.10 if the libvirt software version is 4.6.0-2ubuntu3.7 or earlier.
To fix USN-4021-1 on Ubuntu 19.04, update the libvirt packages to version 5.0.0-1ubuntu2.3 or later.
To fix USN-4021-1 on Ubuntu 18.10, update the libvirt packages to version 4.6.0-2ubuntu3.7 or later.