PT-2019-4806 · Linux+2 · Linux Kernel+2

Julien Grall

·

Published

2019-07-18

·

Updated

2021-05-28

·

CVE-2019-17351

CVSS v3.1

6.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.2.3
Description The issue is related to an uncontrolled resource consumption in the Linux kernel, specifically in the drivers/xen/balloon.c file. This can be exploited to cause a denial of service. The problem arises during the mapping of guest memory, allowing guest OS users to consume resources unrestrictedly.
Recommendations For Linux kernel versions prior to 5.2.3, update to version 5.2.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the drivers/xen/balloon.c file or limiting the resources available to guest OS users to minimize the risk of exploitation.

Fix

DoS

Resource Exhaustion

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-2339
ALT-PU-2019-2366
ALT-PU-2019-2488
ALT-PU-2019-2746
ALT-PU-2020-1198
ALT-PU-2020-1501
ALT-PU-2020-2410
ALT-PU-2020-2433
ALT-PU-2021-1870
BDU:2020-01384
CVE-2019-17351
USN-4286-1
USN-4286-2

Affected Products

Alt Linux
Linux Kernel
Ubuntu