<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 17:02:29 +0000</lastBuildDate>
    <item>
      <title>CVE-2019-10167</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2019-10167</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; libvirt&lt;/p&gt;
&lt;p&gt;The virConnectGetDomainCapabilities() libvirt API, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accepts an &amp;#34;emulatorbin&amp;#34; argument to specify the program providing emulation for a domain. Since v1.2.19, libvirt will execute that program to probe the domain&amp;#39;s capabilities. Read-only clients could specify an arbitrary path for this argument, causing libvirtd to execute a crafted executable with its own privileges.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; libvirt&lt;/p&gt;
&lt;p&gt;The virConnectGetDomainCapabilities() libvirt API, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accepts an &amp;#34;emulatorbin&amp;#34; argument to specify the program providing emulation for a domain. Since v1.2.19, libvirt will execute that program to probe the domain&amp;#39;s capabilities. Read-only clients could specify an arbitrary path for this argument, causing libvirtd to execute a crafted executable with its own privileges.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2019-10167</guid>
    </item>
    <item>
      <title>USN-4047-1 — libvirt vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/usn-4047-1</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: libvirt, Ubuntu:18.04:LTS: libvirt&lt;/p&gt;
&lt;p&gt;Matthias Gerstner and Ján Tomko discovered that libvirt incorrectly handled
certain API calls. An attacker could possibly use this issue to check for
arbitrary files, or execute arbitrary binaries. In the default
installation, attackers would be isolated by the libvirt AppArmor profile.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: libvirt, Ubuntu:18.04:LTS: libvirt&lt;/p&gt;
&lt;p&gt;Matthias Gerstner and Ján Tomko discovered that libvirt incorrectly handled
certain API calls. An attacker could possibly use this issue to check for
arbitrary files, or execute arbitrary binaries. In the default
installation, attackers would be isolated by the libvirt AppArmor profile.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/usn-4047-1</guid>
    </item>
  </channel>
</rss>
