CVE-2019-3840

MEDIUM

libvirt < 5.0.0 - Denial of Service via QEMU Agent Interface Information

Title source: llm
STIX 2.1

Description

A NULL pointer dereference flaw was discovered in libvirt before version 5.0.0 in the way it gets interface information through the QEMU agent. An attacker in a guest VM can use this flaw to crash libvirtd and cause a denial of service.

References (7)

Core 7
Core References
Exploit, Issue Tracking, Patch, Vendor Advisory x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3840
Exploit, Issue Tracking, Third Party Advisory, Vendor Advisory x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=1663051
Exploit, Vendor Advisory x_refsource_confirm
https://www.redhat.com/archives/libvir-list/2019-January/msg00241.html
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00101.html
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00105.html
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2019:2294

Scores

CVSS v3 5.8
EPSS 0.0071
EPSS Percentile 72.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:N/A:H

Details

CWE
CWE-476
Status published
Products (3)
opensuse/leap 15.0
opensuse/leap 42.3
redhat/libvirt < 5.0.0
Published Mar 27, 2019
Tracked Since Feb 18, 2026