CVE-2019-3882
—CVSS 3.1
5.5 medium
EPSS
<1%p44
Published
()
Modified
Description
A flaw was found in the Linux kernel's vfio interface implementation that permits violation of the user's locked memory limit. If a device is bound to a vfio driver, such as vfio-pci, and the local attacker is administratively granted ownership of the device, it may cause a system memory exhaustion and thus a denial of service (DoS). Versions 3.10, 4.14 and 4.18 are vulnerable.
- Vendors
- linuxfedoraprojectdebiancanonicalopensusenetapp
- Products
- linux kernel, fedora, debian linux, ubuntu linux, leap, active iq unified manager for vmware vsphere, hci management node, snapprotect, solidfire, storage replication adapter for clustered data ontap for vmware vsphere, vasa provider for clustered data ontap, virtual storage console for vmware vsphere
- Weakness
- CWE-770
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.