CVE-2019-3886: Fedoraproject Fedora
Medium severity, CVSS 5.4. EPSS: 1.1% chance of exploitation in the next 30 days.
An incorrect permissions check was discovered in libvirt 4.8.0 and above. The readonly permission was allowed to invoke APIs depending on the guest agent, which could lead to potentially disclosing unintended information or denial of service by causing libvirt to block.
Affected products
- Fedoraproject Fedora: version 29 only; version 30 only
- Opensuse Leap: version 42.3 only
- Red Hat Libvirt: from 4.8.0, before 5.3.0 (fixed in 5.3.0)
Published 2019-04-04. Last modified 2026-06-17.