240
VMScore

CVE-2019-20485

Published: 19/03/2020 Updated: 07/11/2023
CVSS v2 Base Score: 2.7 | Impact Score: 2.9 | Exploitability Score: 5.1
CVSS v3 Base Score: 5.7 | Impact Score: 3.6 | Exploitability Score: 2.1
VMScore: 240
Vector: AV:A/AC:L/Au:S/C:N/I:N/A:P

Vulnerability Summary

qemu/qemu_driver.c in libvirt prior to 6.0.0 mishandles the holding of a monitor job during a query to a guest agent, which allows malicious users to cause a denial of service (API blockage).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat libvirt

debian debian linux 8.0

debian debian linux 9.0

debian debian linux 10.0

fedoraproject fedora 31

Vendor Advisories

Debian Bug report logs - #953078 libvirt: CVE-2019-20485 Package: src:libvirt; Maintainer for src:libvirt is Debian Libvirt Maintainers <pkg-libvirt-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 4 Mar 2020 06:54:02 UTC Severity: important Tags: fixed-upstream, ...
Synopsis Moderate: libvirt security and bug fix update Type/Severity Security Advisory: Moderate Topic An update for libvirt is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) ba ...
Synopsis Moderate: virt:rhel and virt-devel:rhel security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic An update for the virt:rhel and virt-devel:rhel modules is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a securi ...
A flaw was found in the way the libvirtd daemon issued the 'suspend' command to a QEMU guest-agent running inside a guest, where it holds a monitor job while issuing the 'suspend' command to a guest-agent A malicious guest-agent may use this flaw to block the libvirt daemon indefinitely, resulting in a denial of service (CVE-2019-20485) A NULL po ...