CVE-2019-10166: Red Hat Enterprise Linux
High severity, CVSS 7.8. EPSS: 0.5% chance of exploitation in the next 30 days.
It was discovered that libvirtd, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, would permit readonly clients to use the virDomainManagedSaveDefineXML() API, which would permit them to modify managed save state files. If a managed save had already been created by a privileged user, a local attacker could modify this file such that libvirtd would execute an arbitrary program when the domain was resumed.
Affected products
- Red Hat Enterprise Linux: version 7.0 only; version 8.0 only
- Red Hat Enterprise Linux Desktop: version 6.0 only; version 7.0 only
- Red Hat Enterprise Linux Server: version 6.0 only; version 7.0 only
- Red Hat Enterprise Linux Server Aus: version 7.6 only
- Red Hat Enterprise Linux Server Eus: version 7.6 only
- Red Hat Enterprise Linux Server Tus: version 7.6 only
- Red Hat Enterprise Linux Workstation: version 6.0 only; version 7.0 only
- Red Hat Libvirt: from 4.0.0, before 4.10.1 (fixed in 4.10.1); from 5.0.0, before 5.4.1 (fixed in 5.4.1)
- Red Hat Virtualization: version 4.3 only
Published 2019-08-02. Last modified 2026-06-17.