#VU19998 Infinite loop in Linux kernel - CVE-2019-3900
Published: August 8, 2019 / Updated: May 30, 2020
Linux kernel
Linux Foundation
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to infinite loop in vhost_net kernel module when processing incoming packets in handle_rx(). A remote attacker with access to guest operating system can stall the vhost_net kernel thread and cause denial of service conditions.
Remediation
External links
- https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.133
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.2
- https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.64
- https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.191
- https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.190