CVE-2019-3886

Description

An incorrect permissions check was discovered in libvirt 4.8.0 and above. The readonly permission was allowed to invoke APIs depending on the guest agent, which could lead to potentially disclosing unintended information or denial of service by causing libvirt to block.

Risk Information

Base Score
5.4
MODERATE
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
EPSS Score
Exploitation Probability
0.481

Associated Vulnerability

VulnerabilityOS Platform
Libvirt virtualization toolkit (USN-4021-1) libvirt0_4.6.0-2ubuntu3.7_i386.debLinux
Libvirt virtualization toolkit (USN-4021-1) libvirt0_4.6.0-2ubuntu3.7_amd64.debLinux
Libvirt virtualization toolkit (USN-4021-1) libvirt0_5.0.0-1ubuntu2.3_i386.debLinux
Libvirt virtualization toolkit (USN-4021-1) libvirt0_5.0.0-1ubuntu2.3_amd64.debLinux
Libvirt virtualization toolkit (USN-4021-1) libvirt-daemon_4.6.0-2ubuntu3.7_i386.debLinux
Libvirt virtualization toolkit (USN-4021-1) libvirt-daemon_4.6.0-2ubuntu3.7_amd64.debLinux
Libvirt virtualization toolkit (USN-4021-1) libvirt-daemon_5.0.0-1ubuntu2.3_i386.debLinux
Libvirt virtualization toolkit (USN-4021-1) libvirt-daemon_5.0.0-1ubuntu2.3_amd64.debLinux
Libvirt virtualization toolkit (USN-4021-1) libvirt-clients_4.6.0-2ubuntu3.7_i386.debLinux
Libvirt virtualization toolkit (USN-4021-1) libvirt-clients_4.6.0-2ubuntu3.7_amd64.debLinux
Libvirt virtualization toolkit (USN-4021-1) libvirt-clients_5.0.0-1ubuntu2.3_i386.debLinux
Libvirt virtualization toolkit (USN-4021-1) libvirt-clients_5.0.0-1ubuntu2.3_amd64.debLinux
SUSE-SU-2019:0948-1(SUSE Linux Enterprise Desktop 12-SP4 ) libvirt-4.0.0-8.9.1.x86_64.rpmLinux
SUSE-SU-2019:0948-1(SUSE Linux Enterprise Desktop 12-SP4 ) libvirt-admin-4.0.0-8.9.1.x86_64.rpmLinux
SUSE-SU-2019:0948-1(SUSE Linux Enterprise Desktop 12-SP4 ) libvirt-admin-debuginfo-4.0.0-8.9.1.x86_64.rpmLinux
SUSE-SU-2019:0948-1(SUSE Linux Enterprise Desktop 12-SP4 ) libvirt-client-4.0.0-8.9.1.x86_64.rpmLinux
SUSE-SU-2019:0948-1(SUSE Linux Enterprise Desktop 12-SP4 ) libvirt-client-debuginfo-4.0.0-8.9.1.x86_64.rpmLinux
SUSE-SU-2019:0948-1(SUSE Linux Enterprise Desktop 12-SP4 ) libvirt-daemon-4.0.0-8.9.1.x86_64.rpmLinux
SUSE-SU-2019:0948-1(SUSE Linux Enterprise Desktop 12-SP4 ) libvirt-daemon-config-network-4.0.0-8.9.1.x86_64.rpmLinux
SUSE-SU-2019:0948-1(SUSE Linux Enterprise Desktop 12-SP4 ) libvirt-daemon-config-nwfilter-4.0.0-8.9.1.x86_64.rpmLinux
SUSE-SU-2019:0948-1(SUSE Linux Enterprise Desktop 12-SP4 ) libvirt-daemon-debuginfo-4.0.0-8.9.1.x86_64.rpmLinux
SUSE-SU-2019:0948-1(SUSE Linux Enterprise Desktop 12-SP4 ) libvirt-daemon-driver-interface-4.0.0-8.9.1.x86_64.rpmLinux
SUSE-SU-2019:0948-1(SUSE Linux Enterprise Desktop 12-SP4 ) libvirt-daemon-driver-interface-debuginfo-4.0.0-8.9.1.x86_64.rpmLinux
SUSE-SU-2019:0948-1(SUSE Linux Enterprise Desktop 12-SP4 ) libvirt-daemon-driver-libxl-4.0.0-8.9.1.x86_64.rpmLinux
SUSE-SU-2019:0948-1(SUSE Linux Enterprise Desktop 12-SP4 ) libvirt-daemon-driver-libxl-debuginfo-4.0.0-8.9.1.x86_64.rpmLinux
SUSE-SU-2019:0948-1(SUSE Linux Enterprise Desktop 12-SP4 ) libvirt-daemon-driver-lxc-4.0.0-8.9.1.x86_64.rpmLinux
SUSE-SU-2019:0948-1(SUSE Linux Enterprise Desktop 12-SP4 ) libvirt-daemon-driver-lxc-debuginfo-4.0.0-8.9.1.x86_64.rpmLinux
SUSE-SU-2019:0948-1(SUSE Linux Enterprise Desktop 12-SP4 ) libvirt-daemon-driver-network-4.0.0-8.9.1.x86_64.rpmLinux
SUSE-SU-2019:0948-1(SUSE Linux Enterprise Desktop 12-SP4 ) libvirt-daemon-driver-network-debuginfo-4.0.0-8.9.1.x86_64.rpmLinux
SUSE-SU-2019:0948-1(SUSE Linux Enterprise Desktop 12-SP4 ) libvirt-daemon-driver-nodedev-4.0.0-8.9.1.x86_64.rpmLinux
SUSE-SU-2019:0948-1(SUSE Linux Enterprise Desktop 12-SP4 ) libvirt-daemon-driver-nodedev-debuginfo-4.0.0-8.9.1.x86_64.rpmLinux
SUSE-SU-2019:0948-1(SUSE Linux Enterprise Desktop 12-SP4 ) libvirt-daemon-driver-nwfilter-4.0.0-8.9.1.x86_64.rpmLinux
SUSE-SU-2019:0948-1(SUSE Linux Enterprise Desktop 12-SP4 ) libvirt-daemon-driver-nwfilter-debuginfo-4.0.0-8.9.1.x86_64.rpmLinux
SUSE-SU-2019:0948-1(SUSE Linux Enterprise Desktop 12-SP4 ) libvirt-daemon-driver-qemu-4.0.0-8.9.1.x86_64.rpmLinux
SUSE-SU-2019:0948-1(SUSE Linux Enterprise Desktop 12-SP4 ) libvirt-daemon-driver-qemu-debuginfo-4.0.0-8.9.1.x86_64.rpmLinux
SUSE-SU-2019:0948-1(SUSE Linux Enterprise Desktop 12-SP4 ) libvirt-daemon-driver-secret-4.0.0-8.9.1.x86_64.rpmLinux
SUSE-SU-2019:0948-1(SUSE Linux Enterprise Desktop 12-SP4 ) libvirt-daemon-driver-secret-debuginfo-4.0.0-8.9.1.x86_64.rpmLinux
SUSE-SU-2019:0948-1(SUSE Linux Enterprise Desktop 12-SP4 ) libvirt-daemon-driver-storage-4.0.0-8.9.1.x86_64.rpmLinux
SUSE-SU-2019:0948-1(SUSE Linux Enterprise Desktop 12-SP4 ) libvirt-daemon-driver-storage-core-4.0.0-8.9.1.x86_64.rpmLinux
SUSE-SU-2019:0948-1(SUSE Linux Enterprise Desktop 12-SP4 ) libvirt-daemon-driver-storage-core-debuginfo-4.0.0-8.9.1.x86_64.rpmLinux
SUSE-SU-2019:0948-1(SUSE Linux Enterprise Desktop 12-SP4 ) libvirt-daemon-driver-storage-disk-4.0.0-8.9.1.x86_64.rpmLinux
SUSE-SU-2019:0948-1(SUSE Linux Enterprise Desktop 12-SP4 ) libvirt-daemon-driver-storage-disk-debuginfo-4.0.0-8.9.1.x86_64.rpmLinux
SUSE-SU-2019:0948-1(SUSE Linux Enterprise Desktop 12-SP4 ) libvirt-daemon-driver-storage-iscsi-4.0.0-8.9.1.x86_64.rpmLinux
SUSE-SU-2019:0948-1(SUSE Linux Enterprise Desktop 12-SP4 ) libvirt-daemon-driver-storage-iscsi-debuginfo-4.0.0-8.9.1.x86_64.rpmLinux
SUSE-SU-2019:0948-1(SUSE Linux Enterprise Desktop 12-SP4 ) libvirt-daemon-driver-storage-logical-4.0.0-8.9.1.x86_64.rpmLinux
SUSE-SU-2019:0948-1(SUSE Linux Enterprise Desktop 12-SP4 ) libvirt-daemon-driver-storage-logical-debuginfo-4.0.0-8.9.1.x86_64.rpmLinux
SUSE-SU-2019:0948-1(SUSE Linux Enterprise Desktop 12-SP4 ) libvirt-daemon-driver-storage-mpath-4.0.0-8.9.1.x86_64.rpmLinux
SUSE-SU-2019:0948-1(SUSE Linux Enterprise Desktop 12-SP4 ) libvirt-daemon-driver-storage-mpath-debuginfo-4.0.0-8.9.1.x86_64.rpmLinux
SUSE-SU-2019:0948-1(SUSE Linux Enterprise Desktop 12-SP4 ) libvirt-daemon-driver-storage-rbd-4.0.0-8.9.1.x86_64.rpmLinux
SUSE-SU-2019:0948-1(SUSE Linux Enterprise Desktop 12-SP4 ) libvirt-daemon-driver-storage-rbd-debuginfo-4.0.0-8.9.1.x86_64.rpmLinux
SUSE-SU-2019:0948-1(SUSE Linux Enterprise Desktop 12-SP4 ) libvirt-daemon-driver-storage-scsi-4.0.0-8.9.1.x86_64.rpmLinux
SUSE-SU-2019:0948-1(SUSE Linux Enterprise Desktop 12-SP4 ) libvirt-daemon-driver-storage-scsi-debuginfo-4.0.0-8.9.1.x86_64.rpmLinux
SUSE-SU-2019:0948-1(SUSE Linux Enterprise Desktop 12-SP4 ) libvirt-daemon-lxc-4.0.0-8.9.1.x86_64.rpmLinux
SUSE-SU-2019:0948-1(SUSE Linux Enterprise Desktop 12-SP4 ) libvirt-daemon-qemu-4.0.0-8.9.1.x86_64.rpmLinux
SUSE-SU-2019:0948-1(SUSE Linux Enterprise Desktop 12-SP4 ) libvirt-daemon-xen-4.0.0-8.9.1.x86_64.rpmLinux
SUSE-SU-2019:0948-1(SUSE Linux Enterprise Desktop 12-SP4 ) libvirt-debugsource-4.0.0-8.9.1.x86_64.rpmLinux
SUSE-SU-2019:0948-1(SUSE Linux Enterprise Desktop 12-SP4 ) libvirt-doc-4.0.0-8.9.1.x86_64.rpmLinux
SUSE-SU-2019:0948-1(SUSE Linux Enterprise Desktop 12-SP4 ) libvirt-libs-4.0.0-8.9.1.x86_64.rpmLinux
SUSE-SU-2019:0948-1(SUSE Linux Enterprise Desktop 12-SP4 ) libvirt-libs-debuginfo-4.0.0-8.9.1.x86_64.rpmLinux
SUSE-SU-2019:0948-1(SUSE Linux Enterprise Server 12-SP4 ) libvirt-daemon-hooks-4.0.0-8.9.1.x86_64.rpmLinux
SUSE-SU-2019:0948-1(SUSE Linux Enterprise Server 12-SP4 ) libvirt-lock-sanlock-4.0.0-8.9.1.x86_64.rpmLinux
SUSE-SU-2019:0948-1(SUSE Linux Enterprise Server 12-SP4 ) libvirt-lock-sanlock-debuginfo-4.0.0-8.9.1.x86_64.rpmLinux
SUSE-SU-2019:0948-1(SUSE Linux Enterprise Server 12-SP4 ) libvirt-nss-4.0.0-8.9.1.x86_64.rpmLinux
SUSE-SU-2019:0948-1(SUSE Linux Enterprise Server 12-SP4 ) libvirt-nss-debuginfo-4.0.0-8.9.1.x86_64.rpmLinux
SUSE-SU-2019:1042-1(SUSE Linux Enterprise Desktop 12-SP3 ) libvirt-3.3.0-5.30.1.x86_64.rpmLinux
SUSE-SU-2019:1042-1(SUSE Linux Enterprise Desktop 12-SP3 ) libvirt-admin-3.3.0-5.30.1.x86_64.rpmLinux
SUSE-SU-2019:1042-1(SUSE Linux Enterprise Desktop 12-SP3 ) libvirt-admin-debuginfo-3.3.0-5.30.1.x86_64.rpmLinux
SUSE-SU-2019:1042-1(SUSE Linux Enterprise Desktop 12-SP3 ) libvirt-client-3.3.0-5.30.1.x86_64.rpmLinux
SUSE-SU-2019:1042-1(SUSE Linux Enterprise Desktop 12-SP3 ) libvirt-client-debuginfo-3.3.0-5.30.1.x86_64.rpmLinux
SUSE-SU-2019:1042-1(SUSE Linux Enterprise Desktop 12-SP3 ) libvirt-daemon-3.3.0-5.30.1.x86_64.rpmLinux
SUSE-SU-2019:1042-1(SUSE Linux Enterprise Desktop 12-SP3 ) libvirt-daemon-config-network-3.3.0-5.30.1.x86_64.rpmLinux
SUSE-SU-2019:1042-1(SUSE Linux Enterprise Desktop 12-SP3 ) libvirt-daemon-config-nwfilter-3.3.0-5.30.1.x86_64.rpmLinux
SUSE-SU-2019:1042-1(SUSE Linux Enterprise Desktop 12-SP3 ) libvirt-daemon-debuginfo-3.3.0-5.30.1.x86_64.rpmLinux
SUSE-SU-2019:1042-1(SUSE Linux Enterprise Desktop 12-SP3 ) libvirt-daemon-driver-interface-3.3.0-5.30.1.x86_64.rpmLinux
SUSE-SU-2019:1042-1(SUSE Linux Enterprise Desktop 12-SP3 ) libvirt-daemon-driver-interface-debuginfo-3.3.0-5.30.1.x86_64.rpmLinux
SUSE-SU-2019:1042-1(SUSE Linux Enterprise Desktop 12-SP3 ) libvirt-daemon-driver-libxl-3.3.0-5.30.1.x86_64.rpmLinux
SUSE-SU-2019:1042-1(SUSE Linux Enterprise Desktop 12-SP3 ) libvirt-daemon-driver-libxl-debuginfo-3.3.0-5.30.1.x86_64.rpmLinux
SUSE-SU-2019:1042-1(SUSE Linux Enterprise Desktop 12-SP3 ) libvirt-daemon-driver-lxc-3.3.0-5.30.1.x86_64.rpmLinux
SUSE-SU-2019:1042-1(SUSE Linux Enterprise Desktop 12-SP3 ) libvirt-daemon-driver-lxc-debuginfo-3.3.0-5.30.1.x86_64.rpmLinux
SUSE-SU-2019:1042-1(SUSE Linux Enterprise Desktop 12-SP3 ) libvirt-daemon-driver-network-3.3.0-5.30.1.x86_64.rpmLinux
SUSE-SU-2019:1042-1(SUSE Linux Enterprise Desktop 12-SP3 ) libvirt-daemon-driver-network-debuginfo-3.3.0-5.30.1.x86_64.rpmLinux
SUSE-SU-2019:1042-1(SUSE Linux Enterprise Desktop 12-SP3 ) libvirt-daemon-driver-nodedev-3.3.0-5.30.1.x86_64.rpmLinux
SUSE-SU-2019:1042-1(SUSE Linux Enterprise Desktop 12-SP3 ) libvirt-daemon-driver-nodedev-debuginfo-3.3.0-5.30.1.x86_64.rpmLinux
SUSE-SU-2019:1042-1(SUSE Linux Enterprise Desktop 12-SP3 ) libvirt-daemon-driver-nwfilter-3.3.0-5.30.1.x86_64.rpmLinux
SUSE-SU-2019:1042-1(SUSE Linux Enterprise Desktop 12-SP3 ) libvirt-daemon-driver-nwfilter-debuginfo-3.3.0-5.30.1.x86_64.rpmLinux
SUSE-SU-2019:1042-1(SUSE Linux Enterprise Desktop 12-SP3 ) libvirt-daemon-driver-qemu-3.3.0-5.30.1.x86_64.rpmLinux
SUSE-SU-2019:1042-1(SUSE Linux Enterprise Desktop 12-SP3 ) libvirt-daemon-driver-qemu-debuginfo-3.3.0-5.30.1.x86_64.rpmLinux
SUSE-SU-2019:1042-1(SUSE Linux Enterprise Desktop 12-SP3 ) libvirt-daemon-driver-secret-3.3.0-5.30.1.x86_64.rpmLinux
SUSE-SU-2019:1042-1(SUSE Linux Enterprise Desktop 12-SP3 ) libvirt-daemon-driver-secret-debuginfo-3.3.0-5.30.1.x86_64.rpmLinux
SUSE-SU-2019:1042-1(SUSE Linux Enterprise Desktop 12-SP3 ) libvirt-daemon-driver-storage-3.3.0-5.30.1.x86_64.rpmLinux
SUSE-SU-2019:1042-1(SUSE Linux Enterprise Desktop 12-SP3 ) libvirt-daemon-driver-storage-core-3.3.0-5.30.1.x86_64.rpmLinux
SUSE-SU-2019:1042-1(SUSE Linux Enterprise Desktop 12-SP3 ) libvirt-daemon-driver-storage-core-debuginfo-3.3.0-5.30.1.x86_64.rpmLinux
SUSE-SU-2019:1042-1(SUSE Linux Enterprise Desktop 12-SP3 ) libvirt-daemon-driver-storage-disk-3.3.0-5.30.1.x86_64.rpmLinux
SUSE-SU-2019:1042-1(SUSE Linux Enterprise Desktop 12-SP3 ) libvirt-daemon-driver-storage-disk-debuginfo-3.3.0-5.30.1.x86_64.rpmLinux
SUSE-SU-2019:1042-1(SUSE Linux Enterprise Desktop 12-SP3 ) libvirt-daemon-driver-storage-iscsi-3.3.0-5.30.1.x86_64.rpmLinux
SUSE-SU-2019:1042-1(SUSE Linux Enterprise Desktop 12-SP3 ) libvirt-daemon-driver-storage-iscsi-debuginfo-3.3.0-5.30.1.x86_64.rpmLinux
SUSE-SU-2019:1042-1(SUSE Linux Enterprise Desktop 12-SP3 ) libvirt-daemon-driver-storage-logical-3.3.0-5.30.1.x86_64.rpmLinux
SUSE-SU-2019:1042-1(SUSE Linux Enterprise Desktop 12-SP3 ) libvirt-daemon-driver-storage-logical-debuginfo-3.3.0-5.30.1.x86_64.rpmLinux
SUSE-SU-2019:1042-1(SUSE Linux Enterprise Desktop 12-SP3 ) libvirt-daemon-driver-storage-mpath-3.3.0-5.30.1.x86_64.rpmLinux
SUSE-SU-2019:1042-1(SUSE Linux Enterprise Desktop 12-SP3 ) libvirt-daemon-driver-storage-mpath-debuginfo-3.3.0-5.30.1.x86_64.rpmLinux
SUSE-SU-2019:1042-1(SUSE Linux Enterprise Desktop 12-SP3 ) libvirt-daemon-driver-storage-rbd-3.3.0-5.30.1.x86_64.rpmLinux
SUSE-SU-2019:1042-1(SUSE Linux Enterprise Desktop 12-SP3 ) libvirt-daemon-driver-storage-rbd-debuginfo-3.3.0-5.30.1.x86_64.rpmLinux
SUSE-SU-2019:1042-1(SUSE Linux Enterprise Desktop 12-SP3 ) libvirt-daemon-driver-storage-scsi-3.3.0-5.30.1.x86_64.rpmLinux
SUSE-SU-2019:1042-1(SUSE Linux Enterprise Desktop 12-SP3 ) libvirt-daemon-driver-storage-scsi-debuginfo-3.3.0-5.30.1.x86_64.rpmLinux
SUSE-SU-2019:1042-1(SUSE Linux Enterprise Desktop 12-SP3 ) libvirt-daemon-lxc-3.3.0-5.30.1.x86_64.rpmLinux
SUSE-SU-2019:1042-1(SUSE Linux Enterprise Desktop 12-SP3 ) libvirt-daemon-qemu-3.3.0-5.30.1.x86_64.rpmLinux
SUSE-SU-2019:1042-1(SUSE Linux Enterprise Desktop 12-SP3 ) libvirt-daemon-xen-3.3.0-5.30.1.x86_64.rpmLinux
SUSE-SU-2019:1042-1(SUSE Linux Enterprise Desktop 12-SP3 ) libvirt-debugsource-3.3.0-5.30.1.x86_64.rpmLinux
SUSE-SU-2019:1042-1(SUSE Linux Enterprise Desktop 12-SP3 ) libvirt-doc-3.3.0-5.30.1.x86_64.rpmLinux
SUSE-SU-2019:1042-1(SUSE Linux Enterprise Desktop 12-SP3 ) libvirt-libs-3.3.0-5.30.1.x86_64.rpmLinux
SUSE-SU-2019:1042-1(SUSE Linux Enterprise Desktop 12-SP3 ) libvirt-libs-debuginfo-3.3.0-5.30.1.x86_64.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234