CVE-2019-3882 - CERT CVE
ID CVE-2019-3882
Sažetak A flaw was found in the Linux kernel's vfio interface implementation that permits violation of the user's locked memory limit. If a device is bound to a vfio driver, such as vfio-pci, and the local attacker is administratively granted ownership of the device, it may cause a system memory exhaustion and thus a denial of service (DoS). Versions 3.10, 4.14 and 4.18 are vulnerable.
Reference
CVSS
Base: 4.9
Impact: 6.9
Exploitability:3.9
Pristup
VektorSloženostAutentikacija
LOCAL LOW NONE
Impact
PovjerljivostCjelovitostDostupnost
NONE NONE COMPLETE
CVSS vektor AV:L/AC:L/Au:N/C:N/I:N/A:C
Zadnje važnije ažuriranje 12-02-2023 - 23:38
Objavljeno 24-04-2019 - 16:29