Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2019-3840

Published: March 27, 2019Last modified: November 9, 2023

Description

A NULL pointer dereference flaw was discovered in libvirt before version 5.0.0 in the way it gets interface information through the QEMU agent. An attacker in a guest VM can use this flaw to crash libvirtd and cause a denial of service.

Severity score breakdown

ParameterValue
Base score6.3
Attack VectorNETWORK
Attack complexityHIGH
Privileges requiredLOW
User interactionNONE
ScopeCHANGED
ConfidentialityNONE
Integrity impactNONE
Availability impactHIGH
VectorCVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSlibvirtNot affected (8.9.0-r5)
StreamlibvirtNot affected (9.6.0-r0)

References

ON THIS PAGE