A flaw was found in the Linux kernel's vfio interface implementation that permits violation of the user's locked memory limit. If a device is bound to a vfio driver, such as vfio-pci, and the local attacker is administratively granted ownership of the device, it may cause a system memory exhaustion and thus a denial of service (DoS). Versions 3.10, 4.14 and 4.18 are vulnerable.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2019-04-24T15:23:10

Updated: 2024-08-04T19:19:18.633Z

Reserved: 2019-01-03T00:00:00

Link: CVE-2019-3882

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-04-24T16:29:02.450

Modified: 2023-02-12T23:38:23.853

Link: CVE-2019-3882

cve-icon Redhat

Severity : Moderate

Publid Date: 2019-04-02T00:00:00Z

Links: CVE-2019-3882 - Bugzilla