A flaw was found in the Linux kernel's vfio interface implementation that permits violation of the user's locked memory limit. If a device is bound to a vfio driver, such as vfio-pci, and the local attacker is administratively granted ownership of the device, it may cause a system memory exhaustion and thus a denial of service (DoS). Versions 3.10, 4.14 and 4.18 are vulnerable.
Advisories
Source ID Title
Debian DLA Debian DLA DLA-1799-1 linux security update
Debian DLA Debian DLA DLA-1799-2 linux security update
Debian DLA Debian DLA DLA-1885-1 linux-4.9 security update
Debian DSA Debian DSA DSA-4497-1 linux security update
EUVD EUVD EUVD-2019-13492 A flaw was found in the Linux kernel's vfio interface implementation that permits violation of the user's locked memory limit. If a device is bound to a vfio driver, such as vfio-pci, and the local attacker is administratively granted ownership of the device, it may cause a system memory exhaustion and thus a denial of service (DoS). Versions 3.10, 4.14 and 4.18 are vulnerable.
Ubuntu USN Ubuntu USN USN-3979-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-3980-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-3980-2 Linux kernel (HWE) vulnerabilities
Ubuntu USN Ubuntu USN USN-3981-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-3981-2 Linux kernel (HWE) vulnerabilities
Ubuntu USN Ubuntu USN USN-3982-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-3982-2 Linux kernel (Xenial HWE) vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-04T19:19:18.633Z

Reserved: 2019-01-03T00:00:00

Link: CVE-2019-3882

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-04-24T16:29:02.450

Modified: 2024-11-21T04:42:47.350

Link: CVE-2019-3882

cve-icon Redhat

Severity : Moderate

Publid Date: 2019-04-02T00:00:00Z

Links: CVE-2019-3882 - Bugzilla

cve-icon OpenCVE Enrichment

No data.