A flaw was found in the Linux kernel's vfio interface implementation that permits violation of the user's locked memory limit. If a device is bound to a vfio driver, such as vfio-pci, and the local attacker is administratively granted ownership of the device, it may cause a system memory exhaustion and thus a denial of service (DoS). Versions 3.10, 4.14 and 4.18 are vulnerable.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Canonical
Subscribe
|
Ubuntu Linux
Subscribe
|
|
Debian
Subscribe
|
Debian Linux
Subscribe
|
|
Fedoraproject
Subscribe
|
Fedora
Subscribe
|
|
Linux
Subscribe
|
Linux Kernel
Subscribe
|
|
Netapp
Subscribe
|
Active Iq Unified Manager For Vmware Vsphere
Subscribe
Cn1610
Subscribe
Cn1610 Firmware
Subscribe
Hci Management Node
Subscribe
Snapprotect
Subscribe
Solidfire
Subscribe
Storage Replication Adapter For Clustered Data Ontap For Vmware Vsphere
Subscribe
Vasa Provider For Clustered Data Ontap
Subscribe
Virtual Storage Console For Vmware Vsphere
Subscribe
|
|
Opensuse
Subscribe
|
Leap
Subscribe
|
|
Redhat
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1799-1 | linux security update |
Debian DLA |
DLA-1799-2 | linux security update |
Debian DLA |
DLA-1885-1 | linux-4.9 security update |
Debian DSA |
DSA-4497-1 | linux security update |
EUVD |
EUVD-2019-13492 | A flaw was found in the Linux kernel's vfio interface implementation that permits violation of the user's locked memory limit. If a device is bound to a vfio driver, such as vfio-pci, and the local attacker is administratively granted ownership of the device, it may cause a system memory exhaustion and thus a denial of service (DoS). Versions 3.10, 4.14 and 4.18 are vulnerable. |
Ubuntu USN |
USN-3979-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-3980-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-3980-2 | Linux kernel (HWE) vulnerabilities |
Ubuntu USN |
USN-3981-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-3981-2 | Linux kernel (HWE) vulnerabilities |
Ubuntu USN |
USN-3982-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-3982-2 | Linux kernel (Xenial HWE) vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-04T19:19:18.633Z
Reserved: 2019-01-03T00:00:00
Link: CVE-2019-3882
No data.
Status : Modified
Published: 2019-04-24T16:29:02.450
Modified: 2024-11-21T04:42:47.350
Link: CVE-2019-3882
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Ubuntu USN