ZeroHour

CVE-2019-3882

CVSS 3.1
5.5 medium
EPSS
<1%p44
Published
()
Modified
Description

A flaw was found in the Linux kernel's vfio interface implementation that permits violation of the user's locked memory limit. If a device is bound to a vfio driver, such as vfio-pci, and the local attacker is administratively granted ownership of the device, it may cause a system memory exhaustion and thus a denial of service (DoS). Versions 3.10, 4.14 and 4.18 are vulnerable.

Vendors
linuxfedoraprojectdebiancanonicalopensusenetapp
Products
linux kernel, fedora, debian linux, ubuntu linux, leap, active iq unified manager for vmware vsphere, hci management node, snapprotect, solidfire, storage replication adapter for clustered data ontap for vmware vsphere, vasa provider for clustered data ontap, virtual storage console for vmware vsphere
Weakness
CWE-770
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.