← Volver a CVEs
CVE-2019-3882
MEDIUM5.5
Descripcion
A flaw was found in the Linux kernel's vfio interface implementation that permits violation of the user's locked memory limit. If a device is bound to a vfio driver, such as vfio-pci, and the local attacker is administratively granted ownership of the device, it may cause a system memory exhaustion and thus a denial of service (DoS). Versions 3.10, 4.14 and 4.18 are vulnerable.
Detalles CVE
Puntuacion CVSS v3.15.5
SeveridadMEDIUM
Vector CVSSCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Vector de ataqueLOCAL
ComplejidadLOW
Privilegios requeridosLOW
Interaccion usuarioNONE
Publicado4/24/2019
Ultima modificacion11/21/2024
Fuentenvd
Avistamientos honeypot0
Productos afectados
canonical:ubuntu_linuxdebian:debian_linuxfedoraproject:fedoralinux:linux_kernelnetapp:active_iq_unified_manager_for_vmware_vspherenetapp:cn1610netapp:cn1610_firmwarenetapp:hci_management_nodenetapp:snapprotectnetapp:solidfirenetapp:storage_replication_adapter_for_clustered_data_ontap_for_vmware_vspherenetapp:vasa_provider_for_clustered_data_ontapnetapp:virtual_storage_console_for_vmware_vsphereopensuse:leap
Debilidades (CWE)
CWE-770CWE-770
Referencias
http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00037.html(secalert@redhat.com)
http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00043.html(secalert@redhat.com)
http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00071.html(secalert@redhat.com)
https://access.redhat.com/errata/RHSA-2019:2029(secalert@redhat.com)
https://access.redhat.com/errata/RHSA-2019:2043(secalert@redhat.com)
https://access.redhat.com/errata/RHSA-2019:3309(secalert@redhat.com)
https://access.redhat.com/errata/RHSA-2019:3517(secalert@redhat.com)
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3882(secalert@redhat.com)
https://lists.debian.org/debian-lts-announce/2019/05/msg00041.html(secalert@redhat.com)
https://lists.debian.org/debian-lts-announce/2019/05/msg00042.html(secalert@redhat.com)
https://lists.debian.org/debian-lts-announce/2019/08/msg00017.html(secalert@redhat.com)
https://seclists.org/bugtraq/2019/Aug/18(secalert@redhat.com)
https://security.netapp.com/advisory/ntap-20190517-0005/(secalert@redhat.com)
https://usn.ubuntu.com/3979-1/(secalert@redhat.com)
https://usn.ubuntu.com/3980-1/(secalert@redhat.com)
https://usn.ubuntu.com/3980-2/(secalert@redhat.com)
https://usn.ubuntu.com/3981-1/(secalert@redhat.com)
https://usn.ubuntu.com/3981-2/(secalert@redhat.com)
https://usn.ubuntu.com/3982-1/(secalert@redhat.com)
https://usn.ubuntu.com/3982-2/(secalert@redhat.com)
https://www.debian.org/security/2019/dsa-4497(secalert@redhat.com)
http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00037.html(af854a3a-2127-422b-91ae-364da2661108)
http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00043.html(af854a3a-2127-422b-91ae-364da2661108)
http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00071.html(af854a3a-2127-422b-91ae-364da2661108)
https://access.redhat.com/errata/RHSA-2019:2029(af854a3a-2127-422b-91ae-364da2661108)
https://access.redhat.com/errata/RHSA-2019:2043(af854a3a-2127-422b-91ae-364da2661108)
https://access.redhat.com/errata/RHSA-2019:3309(af854a3a-2127-422b-91ae-364da2661108)
https://access.redhat.com/errata/RHSA-2019:3517(af854a3a-2127-422b-91ae-364da2661108)
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3882(af854a3a-2127-422b-91ae-364da2661108)
https://lists.debian.org/debian-lts-announce/2019/05/msg00041.html(af854a3a-2127-422b-91ae-364da2661108)
https://lists.debian.org/debian-lts-announce/2019/05/msg00042.html(af854a3a-2127-422b-91ae-364da2661108)
https://lists.debian.org/debian-lts-announce/2019/08/msg00017.html(af854a3a-2127-422b-91ae-364da2661108)
https://seclists.org/bugtraq/2019/Aug/18(af854a3a-2127-422b-91ae-364da2661108)
https://security.netapp.com/advisory/ntap-20190517-0005/(af854a3a-2127-422b-91ae-364da2661108)
https://usn.ubuntu.com/3979-1/(af854a3a-2127-422b-91ae-364da2661108)
https://usn.ubuntu.com/3980-1/(af854a3a-2127-422b-91ae-364da2661108)
https://usn.ubuntu.com/3980-2/(af854a3a-2127-422b-91ae-364da2661108)
https://usn.ubuntu.com/3981-1/(af854a3a-2127-422b-91ae-364da2661108)
https://usn.ubuntu.com/3981-2/(af854a3a-2127-422b-91ae-364da2661108)
https://usn.ubuntu.com/3982-1/(af854a3a-2127-422b-91ae-364da2661108)
https://usn.ubuntu.com/3982-2/(af854a3a-2127-422b-91ae-364da2661108)
https://www.debian.org/security/2019/dsa-4497(af854a3a-2127-422b-91ae-364da2661108)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.