Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2019-20485

21
FAUCET Score

CVE-2019-20485 describes a denial-of-service vulnerability in libvirt versions prior to 6.0.0, specifically within the qemu/qemu_driver.c component, affecting various Debian, Fedora, and Red Hat distributions. This flaw allows an authenticated attacker on the adjacent network to block the API by mishandling a monitor job during a guest agent query. Rated as Medium severity (CVSS 5.7), the vulnerability has a low attack complexity and requires low privileges, leading to high availability impact. There is no evidence of active exploitation, public exploit code, or significant community discussion or media coverage for this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
< 6.0.0CPE matchmatch criteria
cpe:2.3:a:redhat:libvirt:*:*:*:*:*:*:*:*
8.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
9.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
10.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
31CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.7MEDIUM

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
2.1
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.81%
Probability of exploitation in next 30 days
EPSS Percentile
53.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0081 is in the 83rd percentile among its peer group of 314 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (7)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: libvirt-0:4.5.0-36.el7
View patch
redhatpatch availablevia redhat_api
Product: Advanced Virtualization for RHEL 8.2.0Fixed in: virt:8.2-8020020200414225921.6a468ee4
View patch
redhatpatch availablevia redhat_api
Product: Advanced Virtualization for RHEL 8.2.0Fixed in: virt-devel:8.2-8020020200414225921.6a468ee4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: virt-devel:rhel-8030020200909014558.30b713e6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: virt:rhel-8030020200909014558.30b713e6
View patch
redhatvendor investigatingvia nvd_reference
View patch
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 8 Advanced VirtualizationFixed in: virt:8.1/libvirt

Vendor Advisories (1)

redhatCVE-2019-20485Moderate

libvirt: Potential DoS by holding a monitor job while querying QEMU guest-agent

Dec 5, 2019

References

bugs.debian.org / cgi-bin/bugreport.cgi
Issue TrackingThird Party Advisory
bugzilla.redhat.com / show_bug.cgi
Issue TrackingVendor Advisory
libvirt.org / git
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/D5GE6ISYUL3CIWO3FQRUGMKTKP2NYED2
security-tracker.debian.org / tracker/CVE-2019-20485
Third Party Advisory
mail-archive.com / debian-bugs-dist%40lists.debian.org/msg1730509.html