PT-2019-3456 · Linux+5 · Linux Kernel+5

Alex Williamson

·

Published

2019-04-02

·

Updated

2024-06-15

·

CVE-2019-3882

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions 3.10, 4.14, and 4.18
Description A flaw in the Linux kernel's vfio interface implementation allows for the violation of a user's locked memory limit, potentially causing system memory exhaustion and a denial of service (DoS). This issue can be exploited if a device is bound to a vfio driver and the attacker has administrative ownership of the device.
Recommendations For version 3.10, update to a fixed version to resolve the issue. For version 4.14, update to a fixed version to resolve the issue. For version 4.18, update to a fixed version to resolve the issue. As a temporary workaround, consider restricting access to vfio drivers, such as vfio-pci, to minimize the risk of exploitation.

Exploit

Fix

DoS

Resource Exhaustion

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1761
ALT-PU-2019-1765
ALT-PU-2019-1766
ALT-PU-2019-1767
ALT-PU-2019-2213
ALT-PU-2019-2234
BDU:2019-03629
CESA-2019_2029
CESA-2019_3309
CESA-2019_3517
CVE-2019-3882
DLA-1799-1
DLA-1799-2
DLA-1885-1
DSA-4497-1
MGASA-2019-0170
MGASA-2019-0171
MGASA-2019-0172
OPENSUSE-SU-2019:1404-1
OPENSUSE-SU-2019:1479-1
OPENSUSE-SU-2019_1404-1
OPENSUSE-SU-2019_1407-1
OPENSUSE-SU-2019_1479-1
OPENSUSE-SU-2024:10728-1
OPENSUSE-SU-2024:13704-1
RHSA-2019:2029
RHSA-2019:2043
RHSA-2019:3309
RHSA-2019:3517
RHSA-2019_2029
RHSA-2019_2043
RHSA-2019_3309
RHSA-2019_3517
SUSE-SU-2019:1240-1
SUSE-SU-2019:1241-1
SUSE-SU-2019:1242-1
SUSE-SU-2019:1244-1
SUSE-SU-2019:1245-1
SUSE-SU-2019:1287-1
SUSE-SU-2019:1289-1
SUSE-SU-2019:1550-1
SUSE-SU-2019:2430-1
USN-3979-1
USN-3980-1
USN-3980-2
USN-3981-1
USN-3981-2
USN-3982-1
USN-3982-2

Affected Products

Alt Linux
Centos
Linux Kernel
Red Hat
Suse
Ubuntu