UBUNTU-CVE-2019-3900
Dashboard / Vulnerabilities / UBUNTU-CVE-2019-3900
UBUNTU-CVE-2019-3900
Summary:
Details: An infinite loop issue was found in the vhost_net kernel module in Linux Kernel up to and including v5.1-rc6, while handling incoming packets in handle_rx(). It could occur if one end sends packets faster than the other end can process them. A guest user, maybe remote one, could use this flaw to stall the vhost_net kernel thread, resulting in a DoS scenario.
References: https://ubuntu.com/security/CVE-2019-3900, https://lore.kernel.org/lkml/[email protected]/, https://lore.kernel.org/lkml/[email protected]/, https://ubuntu.com/security/notices/USN-4114-1, https://ubuntu.com/security/notices/USN-4115-1, https://ubuntu.com/security/notices/USN-4116-1, https://ubuntu.com/security/notices/USN-4117-1, https://ubuntu.com/security/notices/USN-4118-1, https://www.cve.org/CVERecord?id=CVE-2019-3900
Affected packages
Package
Name: linux-azure
Purl: pkg:deb/ubuntu/linux-azure?arch=source&distro=trusty%2Fesm
Affected ranges
Type: ECOSYSTEM
Events:
