MEDIUM · 5.5

CVE-2019-3882

A flaw was found in the Linux kernel's vfio interface implementation that permits violation of the user's locked memory limit. If a device is bound to a vfio driver, such as vfio-pci, and the local at...

Vulnerability Description

A flaw was found in the Linux kernel's vfio interface implementation that permits violation of the user's locked memory limit. If a device is bound to a vfio driver, such as vfio-pci, and the local attacker is administratively granted ownership of the device, it may cause a system memory exhaustion and thus a denial of service (DoS). Versions 3.10, 4.14 and 4.18 are vulnerable.

CVSS Score

5.5

MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
LinuxLinux Kernel3.10
FedoraprojectFedoraAll versions
DebianDebian Linux8.0
CanonicalUbuntu Linux14.04
OpensuseLeap15.0
NetappActive Iq Unified Manager For Vmware Vsphere>= 9.5
NetappHci Management Node-
NetappSnapprotect-
NetappSolidfire-
NetappStorage Replication Adapter For Clustered Data Ontap For Vmware Vsphere>= 7.2
NetappVasa Provider For Clustered Data Ontap>= 7.2
NetappVirtual Storage Console For Vmware Vsphere>= 7.2
NetappCn1610 Firmware-
NetappCn1610-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-3882?

CVE-2019-3882 is a vulnerability with a CVSS score of 5.5 (MEDIUM). A flaw was found in the Linux kernel's vfio interface implementation that permits violation of the user's locked memory limit. If a device is bound to a vfio driver, such as vfio-pci, and the local at...

How severe is CVE-2019-3882?

CVE-2019-3882 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-3882?

Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Fedoraproject Fedora, Debian Debian Linux, Canonical Ubuntu Linux, Opensuse Leap.