CVE-2019-3900

Advisory lineage Upstream: 0 Downstream: 30
Modified
Published: 25 Apr 2019, 14:41
Last modified:04 Aug 2024, 19:26

Vulnerability Summary

Overall Risk (default)
medium
31/100
CVSS Score
7.7 HIGH
v3.1 (nvd)
EPSS Score
0.21% LOW
0% probability +0.12%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

25 Apr 2019, 14:41
Published
Vulnerability first disclosed
04 Aug 2024, 19:26
Last Modified
Vulnerability information updated

Description

An infinite loop issue was found in the vhost_net kernel module in Linux Kernel up to and including v5.1-rc6, while handling incoming packets in handle_rx(). It could occur if one end sends packets faster than the other end can process them. A guest user, maybe remote one, could use this flaw to stall the vhost_net kernel thread, resulting in a DoS scenario.

CVSS Metrics

  • v3.1HIGHScore: 7.7CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
  • v3.0MEDIUMScore: 6.3CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H
  • v2.0MEDIUMScore: 6.8AV:N/AC:L/Au:S/C:N/I:N/A:C

EPSS Trends

Current EPSS score: 0.21% Percentile: 43%

Techniques & Countermeasures

  • CWE-835Loop with Unreachable Exit Condition ('Infinite Loop')

    The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Affected Systems

  • canonicalubuntu_linux

    16.04 | 18.04 | 19.04

  • debiandebian_linux

    8.0 | 9.0 | 10.0

  • fedoraprojectfedora

    29 | 30 | 28

  • linuxlinux_kernel

    ≥ 2.6.34, < 3.16.72 | ≥ 3.17, < 4.4.191 | ≥ 4.5, < 4.9.190 | ≥ 4.10, < 4.14.133 | ≥ 4.15, < 4.19.64 | ≥ 4.20, < 5.2

  • netappactive_iq_unified_manager_for_vmware_vsphere

    ≥ 9.5

  • netappcn1610_firmware

    na

  • netapphci_management_node

    na

  • netappsnapprotect

    na

  • netappsolidfire

    na

  • netappstorage_replication_adapter_for_clustered_data_ontap_for_vmware_vsphere

    ≥ 7.2

  • netappvasa_provider_for_clustered_data_ontap

    ≥ 7.2

  • netappvirtual_storage_console_for_vmware_vsphere

    ≥ 7.2

  • oraclesd-wan_edge

    8.2

  • red hatkernel

    affects up to and including v5.1-rc6

  • redhatenterprise_linux

    6.0 | 7.0

References (29)