Severity
5.5MEDIUM
EPSS
0.0%
top 89.32%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 24
Latest updateMay 24

Description

A flaw was found in the Linux kernel's vfio interface implementation that permits violation of the user's locked memory limit. If a device is bound to a vfio driver, such as vfio-pci, and the local attacker is administratively granted ownership of the device, it may cause a system memory exhaustion and thus a denial of service (DoS). Versions 3.10, 4.14 and 4.18 are vulnerable.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages8 packages

CVEListV5the_linux_foundation/kernel3.10, 4.14, 4.18
NVDlinux/linux_kernel3.10, 4.14, 4.18+2
Debianlinux< 4.19.37-1+3
NVDopensuse/leap15.0, 15.1, 42.3+2

Also affects: Debian Linux 10.0, 8.0, 9.0, Ubuntu Linux 14.04, 16.04, 18.04, 18.10, 19.04

Patches

🔴Vulnerability Details

5
GHSA
GHSA-xmpq-jcv6-q64p: A flaw was found in the Linux kernel's vfio interface implementation that permits violation of the user's locked memory limit2022-05-24
OSV
CVE-2019-3882: A flaw was found in the Linux kernel's vfio interface implementation that permits violation of the user's locked memory limit2019-04-24
CVEList
CVE-2019-3882: A flaw was found in the Linux kernel's vfio interface implementation that permits violation of the user's locked memory limit2019-04-24
Kernel
Merge tag 'vfio-v5.1-rc4' of git://github.com/awilliam/linux-vfio2019-04-05
Kernel
vfio/type1: Limit DMA mappings per container2019-04-03

📋Vendor Advisories

9
Ubuntu
Linux kernel (HWE) vulnerabilities2019-05-15
Ubuntu
Linux kernel vulnerabilities2019-05-14
Ubuntu
Linux kernel (HWE) vulnerabilities2019-05-14
Ubuntu
Linux kernel vulnerabilities2019-05-14
Ubuntu
Linux kernel (Xenial HWE) vulnerabilities2019-05-14

💬Community

2
Bugzilla
CVE-2019-3882 kernel: denial of service vector through vfio DMA mappings [fedora-all]2019-04-03
Bugzilla
CVE-2019-3882 kernel: denial of service vector through vfio DMA mappings2019-03-15
CVE-2019-3882 (MEDIUM CVSS 5.5) | A flaw was found in the Linux kerne | cvebase.io