CVE-2019-10168: Red Hat Enterprise Linux

High severity, CVSS 7.8. EPSS: 0.5% chance of exploitation in the next 30 days.

The virConnectBaselineHypervisorCPU() and virConnectCompareHypervisorCPU() libvirt APIs, 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accept an "emulator" argument to specify the program providing emulation for a domain. Since v1.2.19, libvirt will execute that program to probe the domain's capabilities. Read-only clients could specify an arbitrary path for this argument, causing libvirtd to execute a crafted executable with its own privileges.

Affected products

  • Red Hat Enterprise Linux: version 7.0 only; version 8.0 only
  • Red Hat Enterprise Linux Desktop: version 6.0 only; version 7.0 only
  • Red Hat Enterprise Linux Server: version 6.0 only; version 7.0 only
  • Red Hat Enterprise Linux Server Aus: version 7.6 only
  • Red Hat Enterprise Linux Server Eus: version 7.6 only
  • Red Hat Enterprise Linux Server Tus: version 7.6 only
  • Red Hat Enterprise Linux Workstation: version 6.0 only; version 7.0 only
  • Red Hat Libvirt: from 4.0.0, before 4.10.1 (fixed in 4.10.1); from 5.0.0, before 5.4.1 (fixed in 5.4.1)
  • Red Hat Virtualization: version 4.3 only

Published 2019-08-02. Last modified 2026-06-17.