cbcvebase.
CVE-2018-20784
published 2019-02-22

CVE-2018-20784: In the Linux kernel before 4.20.2, kernel/sched/fair.c mishandles leaf cfs_rq's, which allows attackers to cause a denial of service (infinite loop in…

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
In the Linux kernel before 4.20.2, kernel/sched/fair.c mishandles leaf cfs_rq's, which allows attackers to cause a denial of service (infinite loop in update_blocked_averages) or possibly have unspecified other impact by inducing a high load.

Affected

17 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debianlinux< linux 4.19.16-1 (bookworm)linux 4.19.16-1 (bookworm)
linuxlinux_kernel
linuxlinux_kernel>= 0 < 4.19.16-14.19.16-1
linuxlinux_kernel>= 0 < 4.19.16-14.19.16-1
linuxlinux_kernel>= 0 < 4.19.16-14.19.16-1
linuxlinux_kernel>= 0 < 4.19.16-14.19.16-1
linuxlinux_kernel>= 0 < 4.4.0-170.1994.4.0-170.199
linuxlinux_kernel>= 0 < 4.15.0-62.694.15.0-62.69
linuxlinux_kernel>= 0 < 4.15.0-60.674.15.0-60.67
linuxlinux_kernel>= 4.13 < 4.14.934.14.93
linuxlinux_kernel>= 4.19 < 4.19.154.19.15
linuxlinux_kernel>= 4.20 < 4.20.24.20.2
redhatenterprise_linux
redhatenterprise_linux_for_real_time

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL