CVE-2019-3840

medium
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

A NULL pointer dereference flaw was discovered in libvirt before version 5.0.0 in the way it gets interface information through the QEMU agent. An attacker in a guest VM can use this flaw to crash libvirtd and cause a denial of service.

References

http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00101.html

http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00105.html

https://access.redhat.com/errata/RHSA-2019:2294

https://bugzilla.redhat.com/show_bug.cgi?id=1663051

https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3840

https://lists.fedoraproject.org/archives/list/[email protected]/message/TZRP2BRMI4RYFRPNFTTIAAUOGVN2ORP7/

https://www.redhat.com/archives/libvir-list/2019-January/msg00241.html

Details

Source: MITRE

Published: 2019-03-27

Updated: 2019-05-05

Type: CWE-476

Risk Information

CVSS v2

Base Score: 3.5

Vector: AV:N/AC:M/Au:S/C:N/I:N/A:P

Impact Score: 2.9

Exploitability Score: 6.8

Severity: LOW

CVSS v3

Base Score: 6.3

Vector: CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H

Impact Score: 4

Exploitability Score: 1.8

Severity: MEDIUM

Tenable Plugins

View all (18 total)

IDNameProductFamilySeverity
131029Amazon Linux 2 : libvirt (ALAS-2019-1361)NessusAmazon Linux Local Security Checks
medium
129213EulerOS 2.0 SP3 : libvirt (EulerOS-SA-2019-2020)NessusHuawei Local Security Checks
high
128386CentOS 7 : libvirt (CESA-2019:2294)NessusCentOS Local Security Checks
medium
128237Scientific Linux Security Update : libvirt on SL7.x x86_64 (20190806)NessusScientific Linux Local Security Checks
medium
127708RHEL 7 : libvirt (RHSA-2019:2294)NessusRed Hat Local Security Checks
medium
126852EulerOS 2.0 SP2 : libvirt (EulerOS-SA-2019-1724)NessusHuawei Local Security Checks
high
126425EulerOS 2.0 SP5 : libvirt (EulerOS-SA-2019-1684)NessusHuawei Local Security Checks
medium
126280EulerOS 2.0 SP8 : libvirt (EulerOS-SA-2019-1653)NessusHuawei Local Security Checks
medium
126198Photon OS 1.0: Libvirt PHSA-2019-1.0-0237NessusPhotonOS Local Security Checks
high
124959EulerOS Virtualization 3.0.1.0 : libvirt (EulerOS-SA-2019-1456)NessusHuawei Local Security Checks
high
124745EulerOS Virtualization 2.5.3 : libvirt (EulerOS-SA-2019-1367)NessusHuawei Local Security Checks
medium
124402openSUSE Security Update : libvirt (openSUSE-2019-1294)NessusSuSE Local Security Checks
medium
124361SUSE SLED12 / SLES12 Security Update : libvirt (SUSE-SU-2019:1042-1)NessusSuSE Local Security Checks
medium
124359openSUSE Security Update : libvirt (openSUSE-2019-1288)NessusSuSE Local Security Checks
medium
124082SUSE SLED12 / SLES12 Security Update : libvirt (SUSE-SU-2019:0948-1)NessusSuSE Local Security Checks
medium
124055SUSE SLED15 / SLES15 Security Update : libvirt (SUSE-SU-2019:0936-1)NessusSuSE Local Security Checks
medium
123780SUSE SLES12 Security Update : libvirt (SUSE-SU-2019:0553-1)NessusSuSE Local Security Checks
medium
122868Ubuntu 16.04 LTS / 18.04 LTS / 18.10 : libvirt vulnerability (USN-3909-1)NessusUbuntu Local Security Checks
medium