ZeroHour

CVE-2019-3874

CVSS 3.1
6.5 medium
EPSS
2%p77
Published
()
Modified
Description

The SCTP socket buffer used by a userspace application is not accounted by the cgroups subsystem. An attacker can use this flaw to cause a denial of service attack. Kernel 3.10.x and 4.18.x branches are believed to be vulnerable.

Vendors
linuxdebianredhatcanonicalnetapp
Products
linux kernel, debian linux, enterprise linux, ubuntu linux, active iq unified manager for vmware vsphere, hci management node, snapprotect, solidfire, cn1610 firmware
Weakness
CWE-400
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.