PT-2019-3457 · Linux+5 · Linux Kernel+5

Published

2019-04-24

·

Updated

2024-04-26

·

CVE-2019-3900

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux Kernel versions up to and including v5.1-rc6
Description The issue is related to an infinite loop in the vhost net kernel module when handling incoming packets in the handle rx() function. This can happen if one end sends packets faster than the other end can process them. A guest user, potentially remote, could exploit this flaw to stall the vhost net kernel thread, resulting in a denial-of-service scenario. The vulnerability is associated with uncontrolled resource consumption during packet processing, allowing a remote attacker to cause a service disruption.
Recommendations For Linux Kernel versions up to and including v5.1-rc6, consider applying configuration changes to limit the impact of the infinite loop issue in the vhost net kernel module, such as adjusting packet processing rates or implementing rate limiting. As a temporary workaround, consider restricting access to the handle rx() function until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Infinite Loop

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1893
ALT-PU-2019-1896
ALT-PU-2019-2120
ALT-PU-2019-2311
ALT-PU-2019-2382
ALT-PU-2019-2401
ALT-PU-2019-2465
ALT-PU-2019-2481
ALT-PU-2020-1025
ALT-PU-2020-1070
ALT-PU-2020-1198
ALT-PU-2020-1501
ALT-PU-2020-2410
ALT-PU-2020-2433
ALT-PU-2021-1870
BDU:2019-03630
CESA-2019_2029
CESA-2019_3309
CESA-2019_3517
CESA-2019_3836
CVE-2019-3900
DLA-1884-1
DLA-1885-1
DSA-4497-1
MGASA-2019-0221
OPENSUSE-SU-2021:3876-1
OPENSUSE-SU-2021_3876-1
RHSA-2019:1973
RHSA-2019:2029
RHSA-2019:2043
RHSA-2019:3220
RHSA-2019:3309
RHSA-2019:3517
RHSA-2019:3836
RHSA-2019:3967
RHSA-2019:4058
RHSA-2019_2029
RHSA-2019_2043
RHSA-2019_3309
RHSA-2019_3517
RHSA-2019_3836
RHSA-2020:0204
SUSE-SU-2021:3192-1
SUSE-SU-2021:3206-1
SUSE-SU-2021:3217-1
SUSE-SU-2021:3876-1
SUSE-SU-2021:3969-1
SUSE-SU-2021:3972-1
SUSE-SU-2022:3263-1
SUSE-SU-2022:3294-1
SUSE-SU-2023:0416-1
USN-4114-1
USN-4115-1
USN-4115-2
USN-4116-1
USN-4117-1
USN-4118-1

Affected Products

Alt Linux
Centos
Linux Kernel
Red Hat
Suse
Ubuntu