CVE-2019-3840: Opensuse Leap

Medium severity, CVSS 6.3. EPSS: 1.5% chance of exploitation in the next 30 days.

A NULL pointer dereference flaw was discovered in libvirt before version 5.0.0 in the way it gets interface information through the QEMU agent. An attacker in a guest VM can use this flaw to crash libvirtd and cause a denial of service.

Affected products

  • Opensuse Leap: version 15.0 only; version 42.3 only
  • Red Hat Libvirt: before 5.0.0 (fixed in 5.0.0)

Published 2019-03-27. Last modified 2026-06-17.