Your submission was sent successfully! Close

CVE-2019-10167

Published: 20 June 2019

The virConnectGetDomainCapabilities() libvirt API, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accepts an "emulatorbin" argument to specify the program providing emulation for a domain. Since v1.2.19, libvirt will execute that program to probe the domain's capabilities. Read-only clients could specify an arbitrary path for this argument, causing libvirtd to execute a crafted executable with its own privileges.

Priority

Medium

CVSS 3 base score: 7.8

Status

Package Release Status
libvirt
Launchpad, Ubuntu, Debian
bionic
Released (4.0.0-1ubuntu8.12)
cosmic
Released (4.6.0-2ubuntu3.8)
disco
Released (5.0.0-1ubuntu2.4)
eoan
Released (5.4.0-0ubuntu3)
precise Not vulnerable

trusty Not vulnerable

upstream Needs triage

xenial
Released (1.3.1-1ubuntu10.27)