PT-2019-4806 · Linux+2 · Linux Kernel+2

Julien Grall

·

Publicado

2019-07-18

·

Atualizado

2021-05-28

·

CVE-2019-17351

CVSS v3.1

6.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.2.3
Description The issue is related to an uncontrolled resource consumption in the Linux kernel, specifically in the drivers/xen/balloon.c file. This can be exploited to cause a denial of service. The problem arises during the mapping of guest memory, allowing guest OS users to consume resources unrestrictedly.
Recommendations For Linux kernel versions prior to 5.2.3, update to version 5.2.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the drivers/xen/balloon.c file or limiting the resources available to guest OS users to minimize the risk of exploitation.

Correção

DoS

Resource Exhaustion

Allocation of Resources Without Limits

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2019-2339
ALT-PU-2019-2366
ALT-PU-2019-2488
ALT-PU-2019-2746
ALT-PU-2020-1198
ALT-PU-2020-1501
ALT-PU-2020-2410
ALT-PU-2020-2433
ALT-PU-2021-1870
BDU:2020-01384
CVE-2019-17351
USN-4286-1
USN-4286-2

Produtos afetados

Alt Linux
Linux Kernel
Ubuntu