PT-2020-2426 · Linux+2 · Linux Kernel+2

Rohit Keshri

·

Published

2020-05-09

·

Updated

2026-03-14

·

CVE-2019-20794

CVSS v3.1

4.7

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions 4.18 through 5.6.11
Description An issue in the Linux kernel allows a user to create their own PID namespace and mount a FUSE filesystem. If the userspace component is terminated via a kill of the PID namespace's pid 1, it results in a hung task and resources being permanently locked up until system reboot, leading to resource exhaustion. This issue is related to uncontrolled resource consumption in the FUSE filesystem implementation.
Recommendations For Linux kernel versions 4.18 through 5.6.11, consider disabling the FUSE filesystem feature until a patch is available to prevent resource exhaustion. As a temporary workaround, restrict the use of unprivileged user namespaces to minimize the risk of exploitation. Avoid terminating the userspace component of the FUSE filesystem via a kill of the PID namespace's pid 1 to prevent hung tasks and resource lockup.

Exploit

Fix

Missing Release of Resource after Effective Lifetime

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-1944
ALT-PU-2020-1950
ALT-PU-2020-2153
ALT-PU-2020-2155
ALT-PU-2020-2158
ALT-PU-2020-2164
ALT-PU-2021-1621
ALT-PU-2021-1656
ALT-PU-2021-1739
ALT-PU-2021-1862
ALT-PU-2021-1866
ALT-PU-2021-1870
BDU:2020-02428
CVE-2019-20794
ECHO-541A-6720-4DCA

Affected Products

Alt Linux
Debian
Linux Kernel