A flaw was found in the Linux kernel's vfio interface implementation that permits violation of the user's locked memory limit. If a device is bound to a vfio driver, such as vfio-pci, and the local attacker is administratively granted ownership of the device, it may cause a system memory exhaustion and thus a denial of service (DoS). Versions 3.10, 4.14 and 4.18 are vulnerable.
2019-04-24T16:29:02.450
2024-11-21T04:42:47.350
Modified
CVSSv3.1: 5.5 (MEDIUM)
AV:L/AC:L/Au:N/C:N/I:N/A:C
3.9
6.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | linux | linux_kernel | 3.10 | Yes |
| Operating System | linux | linux_kernel | 4.14 | Yes |
| Operating System | linux | linux_kernel | 4.18 | Yes |
| Operating System | fedoraproject | fedora | * | Yes |
| Operating System | debian | debian_linux | 8.0 | Yes |
| Operating System | debian | debian_linux | 9.0 | Yes |
| Operating System | debian | debian_linux | 10.0 | Yes |
| Operating System | canonical | ubuntu_linux | 14.04 | Yes |
| Operating System | canonical | ubuntu_linux | 16.04 | Yes |
| Operating System | canonical | ubuntu_linux | 18.04 | Yes |
| Operating System | canonical | ubuntu_linux | 18.10 | Yes |
| Operating System | canonical | ubuntu_linux | 19.04 | Yes |
| Operating System | opensuse | leap | 15.0 | Yes |
| Operating System | opensuse | leap | 15.1 | Yes |
| Operating System | opensuse | leap | 42.3 | Yes |
| Application | netapp | active_iq_unified_manager_for_vmware_vsphere | ≥ 9.5 | Yes |
| Application | netapp | hci_management_node | - | Yes |
| Application | netapp | snapprotect | - | Yes |
| Application | netapp | solidfire | - | Yes |
| Application | netapp | storage_replication_adapter_for_clustered_data_ontap_for_vmware_vsphere | ≥ 7.2 | Yes |
| Application | netapp | vasa_provider_for_clustered_data_ontap | ≥ 7.2 | Yes |
| Application | netapp | virtual_storage_console_for_vmware_vsphere | ≥ 7.2 | Yes |
| Operating System | netapp | cn1610_firmware | - | Yes |
| Hardware | netapp | cn1610 | - | No |