CVE-2019-3900

CWE-83517 documents10 sources
Severity
7.7HIGH
EPSS
0.2%
top 57.02%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 25
Latest updateMay 24

Description

An infinite loop issue was found in the vhost_net kernel module in Linux Kernel up to and including v5.1-rc6, while handling incoming packets in handle_rx(). It could occur if one end sends packets faster than the other end can process them. A guest user, maybe remote one, could use this flaw to stall the vhost_net kernel thread, resulting in a DoS scenario.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:HExploitability: 3.1 | Impact: 4.0

Affected Packages8 packages

NVDlinux/linux_kernel2.6.343.16.72+5
CVEListV5red_hat/kernelaffects up to and including v5.1-rc6
Debianlinux< 5.2.6-1+3

Also affects: Debian Linux 10.0, 8.0, 9.0, Ubuntu Linux 16.04, 18.04, 19.04, Enterprise Linux 6.0, 7.0, Fedora 28, 29, 30

Patches

🔴Vulnerability Details

6
GHSA
GHSA-h25g-v6rp-rj4h: An infinite loop issue was found in the vhost_net kernel module in Linux Kernel up to and including v52022-05-24
Kernel
vhost: vsock: add weight support2019-05-17
Kernel
vhost_net: fix possible infinite loop2019-05-17
Kernel
vhost: scsi: add weight support2019-05-17
OSV
CVE-2019-3900: An infinite loop issue was found in the vhost_net kernel module in Linux Kernel up to and including v52019-04-25

📋Vendor Advisories

8
Oracle
Oracle Oracle Communications Risk Matrix: OS (Linux Kernel) — CVE-2019-39002021-04-15
Ubuntu
Linux kernel vulnerabilities2019-09-02
Ubuntu
Linux kernel (AWS) vulnerabilities2019-09-02
Ubuntu
Linux kernel (AWS) vulnerabilities2019-09-02
Ubuntu
Linux kernel vulnerabilities2019-09-02

💬Community

2
Bugzilla
CVE-2019-3900 kernel: vhost_net: infinite loop while receiving packets leads to DoS [fedora-all]2019-04-25
Bugzilla
CVE-2019-3900 Kernel: vhost_net: infinite loop while receiving packets leads to DoS2019-04-11