{"api_version":"1","generated_at":"2026-07-23T10:01:44+00:00","cve":"CVE-2019-3886","urls":{"html":"https://cve.report/CVE-2019-3886","api":"https://cve.report/api/cve/CVE-2019-3886.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-3886","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-3886"},"summary":{"title":"CVE-2019-3886","description":"An incorrect permissions check was discovered in libvirt 4.8.0 and above. The readonly permission was allowed to invoke APIs depending on the guest agent, which could lead to potentially disclosing unintended information or denial of service by causing libvirt to block.","state":"PUBLIC","assigner":"secalert@redhat.com","published_at":"2019-04-04 16:29:00","updated_at":"2023-02-12 23:38:00"},"problem_types":["CWE-862"],"metrics":[],"references":[{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CYMNKXAUBZCFBBPFH64FJPH5EJH4GSU2/","name":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CYMNKXAUBZCFBBPFH64FJPH5EJH4GSU2/","refsource":"MISC","tags":[],"title":"[SECURITY] Fedora 29 Update: libvirt-4.7.0-5.fc29 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/R5DHYIFECZ7BMVXK4EP4FDFZXK7I5MZH/","name":"FEDORA-2019-b2dfb13daf","refsource":"FEDORA","tags":["Mailing List","Third Party Advisory"],"title":"[SECURITY] Fedora 30 Update: libvirt-5.1.0-9.fc30 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CYMNKXAUBZCFBBPFH64FJPH5EJH4GSU2/","name":"FEDORA-2019-9210998aaa","refsource":"FEDORA","tags":["Third Party Advisory"],"title":"[SECURITY] Fedora 29 Update: libvirt-4.7.0-5.fc29 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3886","name":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3886","refsource":"CONFIRM","tags":["Exploit","Issue Tracking","Patch","Third Party Advisory"],"title":"1694880 – (CVE-2019-3886) CVE-2019-3886 libvirt: virsh domhostname command discloses guest hostname in readonly mode","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1694880","name":"https://bugzilla.redhat.com/show_bug.cgi?id=1694880","refsource":"MISC","tags":[],"title":"1694880 – (CVE-2019-3886) CVE-2019-3886 libvirt: virsh domhostname command discloses guest hostname in readonly mode","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://access.redhat.com/errata/RHBA-2019:3723","name":"RHBA-2019:3723","refsource":"REDHAT","tags":["Third Party Advisory"],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00105.html","name":"openSUSE-SU-2019:1294","refsource":"SUSE","tags":["Mailing List","Third Party Advisory"],"title":"[security-announce] openSUSE-SU-2019:1294-1: moderate: Security update f","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://access.redhat.com/security/cve/CVE-2019-3886","name":"https://access.redhat.com/security/cve/CVE-2019-3886","refsource":"MISC","tags":[],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R5DHYIFECZ7BMVXK4EP4FDFZXK7I5MZH/","name":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R5DHYIFECZ7BMVXK4EP4FDFZXK7I5MZH/","refsource":"MISC","tags":[],"title":"[SECURITY] Fedora 30 Update: libvirt-5.1.0-9.fc30 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/107777","name":"107777","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"libvirt CVE-2019-3886 Security Bypass Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://usn.ubuntu.com/4021-1/","name":"USN-4021-1","refsource":"UBUNTU","tags":["Third Party Advisory"],"title":"USN-4021-1: libvirt vulnerabilities | Ubuntu security notices","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-3886","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-3886","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"3886","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"fedoraproject","cpe5":"fedora","cpe6":"29","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"3886","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"fedoraproject","cpe5":"fedora","cpe6":"30","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"3886","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"opensuse","cpe5":"leap","cpe6":"42.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"3886","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"opensuse","cpe5":"leap","cpe6":"42.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"3886","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"redhat","cpe5":"libvirt","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"3886","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"redhat","cpe5":"libvirt","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2019-3886","qid":"672574","title":"EulerOS Security Update for libvirt (EulerOS-SA-2023-1348)"},{"cve":"CVE-2019-3886","qid":"900071","title":"CBL-Mariner Linux Security Update for libvirt 6.1.0"},{"cve":"CVE-2019-3886","qid":"903233","title":"Common Base Linux Mariner (CBL-Mariner) Security Update for libvirt (2685)"},{"cve":"CVE-2019-3886","qid":"905776","title":"Common Base Linux Mariner (CBL-Mariner) Security Update for libvirt (2685-1)"}]},"source_records":{"cve_program":{"data_version":"4.0","data_type":"CVE","data_format":"MITRE","CVE_data_meta":{"ID":"CVE-2019-3886","ASSIGNER":"secalert@redhat.com","STATE":"PUBLIC"},"description":{"description_data":[{"lang":"eng","value":"An incorrect permissions check was discovered in libvirt 4.8.0 and above. The readonly permission was allowed to invoke APIs depending on the guest agent, which could lead to potentially disclosing unintended information or denial of service by causing libvirt to block."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-862","cweId":"CWE-862"}]}]},"affects":{"vendor":{"vendor_data":[{"vendor_name":"The libvirt Project","product":{"product_data":[{"product_name":"libvirt","version":{"version_data":[{"version_affected":"=","version_value":"4.8.0 and above"}]}}]}}]}},"references":{"reference_data":[{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CYMNKXAUBZCFBBPFH64FJPH5EJH4GSU2/","refsource":"MISC","name":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CYMNKXAUBZCFBBPFH64FJPH5EJH4GSU2/"},{"url":"https://usn.ubuntu.com/4021-1/","refsource":"MISC","name":"https://usn.ubuntu.com/4021-1/"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00105.html","refsource":"MISC","name":"http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00105.html"},{"url":"http://www.securityfocus.com/bid/107777","refsource":"MISC","name":"http://www.securityfocus.com/bid/107777"},{"url":"https://access.redhat.com/errata/RHBA-2019:3723","refsource":"MISC","name":"https://access.redhat.com/errata/RHBA-2019:3723"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3886","refsource":"MISC","name":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3886"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R5DHYIFECZ7BMVXK4EP4FDFZXK7I5MZH/","refsource":"MISC","name":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R5DHYIFECZ7BMVXK4EP4FDFZXK7I5MZH/"}]},"impact":{"cvss":[{"version":"3.0","vectorString":"CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":5.4,"baseSeverity":"MEDIUM"}]}},"nvd":{"publishedDate":"2019-04-04 16:29:00","lastModifiedDate":"2023-02-12 23:38:00","problem_types":["CWE-862"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":5.4,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":2.5},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:A/AC:L/Au:N/C:P/I:N/A:P","accessVector":"ADJACENT_NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"PARTIAL","baseScore":4.8},"severity":"MEDIUM","exploitabilityScore":6.5,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:redhat:libvirt:*:*:*:*:*:*:*:*","versionStartIncluding":"4.8.0","versionEndExcluding":"5.3.0","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:opensuse:leap:42.3:*:*:*:*:*:*:*","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"3886","Ordinal":"141495","Title":"CVE-2019-3886","CVE":"CVE-2019-3886","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"3886","Ordinal":"1","NoteData":"An incorrect permissions check was discovered in libvirt 4.8.0 and above. The readonly permission was allowed to invoke APIs depending on the guest agent, which could lead to potentially disclosing unintended information or denial of service by causing libvirt to block.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"3886","Ordinal":"2","NoteData":"2019-04-04","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"3886","Ordinal":"3","NoteData":"2019-11-26","Type":"Other","Title":"Modified"}]}}}