CVE-2019-3900

CVSS v3.1 7.7 (High)
77% Progress
CVSS v2.0 6.8 (Medium)
68% Progress
EPSS 0.10 % (42th)
0.10% Progress
Affected Products 15
Advisories 67
NVD Status Analyzed

An infinite loop issue was found in the vhost_net kernel module in Linux Kernel up to and including v5.1-rc6, while handling incoming packets in handle_rx(). It could occur if one end sends packets faster than the other end can process them. A guest user, maybe remote one, could use this flaw to stall the vhost_net kernel thread, resulting in a DoS scenario.

Weaknesses
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
CVE Status
PUBLISHED
NVD Status
Analyzed
CNA
Red Hat, Inc.
Published Date
2019-04-25 15:29:00
(5 years ago)
Updated Date
2024-04-26 16:08:45
(4 months ago)

Affected Products

Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Linux Kernel from 2.6.34 version and prior 3.16.72 version cpe:2.3:o:linux:linux_kernel >= 2.6.34 < 3.16.72
  Linux Kernel from 3.17 version and prior 4.4.191 version cpe:2.3:o:linux:linux_kernel >= 3.17 < 4.4.191
  Linux Kernel from 4.5 version and prior 4.9.190 version cpe:2.3:o:linux:linux_kernel >= 4.5 < 4.9.190
  Linux Kernel from 4.10 version and prior 4.14.133 version cpe:2.3:o:linux:linux_kernel >= 4.10 < 4.14.133
  Linux Kernel from 4.15 version and prior 4.19.64 version cpe:2.3:o:linux:linux_kernel >= 4.15 < 4.19.64
  Linux Kernel from 4.20 version and prior 5.2 version cpe:2.3:o:linux:linux_kernel >= 4.20 < 5.2

Configuration #2

    CPE23 From Up To
  Fedoraproject Fedora 29 cpe:2.3:o:fedoraproject:fedora:29
  Fedoraproject Fedora 30 cpe:2.3:o:fedoraproject:fedora:30

Configuration #3

    CPE23 From Up To
  Redhat Enterprise Linux 6.0 cpe:2.3:o:redhat:enterprise_linux:6.0
  Redhat Enterprise Linux 7.0 cpe:2.3:o:redhat:enterprise_linux:7.0

Configuration #4

    CPE23 From Up To
  Debian Linux 8.0 cpe:2.3:o:debian:debian_linux:8.0
  Debian Linux 9.0 cpe:2.3:o:debian:debian_linux:9.0
  Debian Linux 10.0 cpe:2.3:o:debian:debian_linux:10.0

Configuration #5

    CPE23 From Up To
  Canonical Ubuntu Linux 16.04 cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts
  Canonical Ubuntu Linux 18.04 cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts
  Canonical Ubuntu Linux 19.04 cpe:2.3:o:canonical:ubuntu_linux:19.04

Configuration #6

    CPE23 From Up To
  Netapp Active Iq Unified Manager for Vmware Vsphere from 9.5 version cpe:2.3:a:netapp:active_iq_unified_manager_for_vmware_vsphere >= 9.5
  Netapp Hci Management Node cpe:2.3:a:netapp:hci_management_node:-
  Netapp Snapprotect cpe:2.3:a:netapp:snapprotect:-
  Netapp Solidfire cpe:2.3:a:netapp:solidfire:-
  Netapp Storage Replication Adapter for Clustered Data Ontap For Vmware Vsphere from 7.2 version cpe:2.3:a:netapp:storage_replication_adapter_for_clustered_data_ontap_for_vmware_vsphere >= 7.2
  Netapp Vasa Provider for Clustered Data Ontap from 7.2 version cpe:2.3:a:netapp:vasa_provider_for_clustered_data_ontap >= 7.2
  Netapp Virtual Storage Console for Vmware Vsphere from 7.2 version cpe:2.3:a:netapp:virtual_storage_console_for_vmware_vsphere >= 7.2

Configuration #7

AND
    CPE23 From Up To
OR  
  Netapp Cn1610 cpe:2.3:h:netapp:cn1610:-
OR  
  Running on/with
  Netapp Cn1610 Firmware cpe:2.3:o:netapp:cn1610_firmware:-

Configuration #8

    CPE23 From Up To
  Oracle Sd-wan Edge 8.2 cpe:2.3:a:oracle:sd-wan_edge:8.2

Configuration #9

    CPE23 From Up To
  Fedoraproject Fedora 28 cpe:2.3:o:fedoraproject:fedora:28
  Fedoraproject Fedora 29 cpe:2.3:o:fedoraproject:fedora:29
  Fedoraproject Fedora 30 cpe:2.3:o:fedoraproject:fedora:30
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...