6.8
CVSSv2

CVE-2019-3900

Published: 25/04/2019 Updated: 12/02/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.9 | Exploitability Score: 8
CVSS v3 Base Score: 7.7 | Impact Score: 4 | Exploitability Score: 3.1
VMScore: 605
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:C

Vulnerability Summary

It exists that a use-after-free error existed in the block layer subsystem of the Linux kernel when certain failure conditions occurred. A local attacker could possibly use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2018-20856)

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

linux linux kernel 5.1

linux linux kernel

fedoraproject fedora 29

fedoraproject fedora 30

redhat enterprise linux 7.0

redhat enterprise linux 6.0

debian debian linux 8.0

debian debian linux 9.0

debian debian linux 10.0

canonical ubuntu linux 16.04

canonical ubuntu linux 18.04

canonical ubuntu linux 19.04

netapp vasa provider for clustered data ontap

netapp solidfire -

netapp hci management node -

netapp snapprotect -

netapp active iq unified manager for vmware vsphere

netapp virtual storage console for vmware vsphere

netapp storage replication adapter for clustered data ontap for vmware vsphere

netapp cn1610_firmware -

oracle sd-wan edge 8.2

Vendor Advisories

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks CVE-2015-8553 Jan Beulich discovered that CVE-2015-2150 was not completely addressed If a PCI physical function is passed through to a Xen guest, the guest is able to access its memory and I ...
Synopsis Important: kernel-alt security and bug fix update Type/Severity Security Advisory: Important Topic An update for kernel-alt is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System ...
Synopsis Important: kernel security and bug fix update Type/Severity Security Advisory: Important Topic An update for kernel is now available for Red Hat Enterprise Linux 74 Advanced Update Support, Red Hat Enterprise Linux 74 Telco Extended Update Support, and Red Hat Enterprise Linux 74 Update Services ...
Synopsis Important: kernel security and bug fix update Type/Severity Security Advisory: Important Topic An update for kernel is now available for Red Hat Enterprise Linux 6Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) b ...
Synopsis Important: kernel security and bug fix update Type/Severity Security Advisory: Important Topic An update for kernel is now available for Red Hat Enterprise Linux 76 Extended Update SupportRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerabili ...
Synopsis Important: kernel-rt security and bug fix update Type/Severity Security Advisory: Important Topic An update for kernel-rt is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (C ...
Synopsis Important: kernel security, bug fix, and enhancement update Type/Severity Security Advisory: Important Topic An update for kernel is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring S ...
Synopsis Important: kernel security, bug fix, and enhancement update Type/Severity Security Advisory: Important Topic An update for kernel is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring S ...
Synopsis Important: kernel-rt security and bug fix update Type/Severity Security Advisory: Important Topic An update for kernel-rt is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (C ...
Synopsis Important: kernel security and bug fix update Type/Severity Security Advisory: Important Topic An update for kernel is now available for Red Hat Enterprise Linux 80 Update Services for SAP SolutionsRed Hat Product Security has rated this update as having a security impact of Important A Common V ...
Synopsis Important: kernel security and bug fix update Type/Severity Security Advisory: Important Topic An update for kernel is now available for Red Hat Enterprise Linux 75 Extended Update SupportRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerabili ...
An infinite loop issue was found in the vhost_net kernel module while handling incoming packets in handle_rx() The infinite loop could occur if one end sends packets faster than the other end can process them A guest user, maybe a remote one, could use this flaw to stall the vhost_net kernel thread, resulting in a DoS scenario(CVE-2019-3900) A f ...
Several security issues were fixed in the Linux kernel ...
Several security issues were fixed in the Linux kernel ...
An infinite loop issue was found in the vhost_net kernel module while handling incoming packets in handle_rx() The infinite loop could occur if one end sends packets faster than the other end can process them A guest user, maybe a remote one, could use this flaw to stall the vhost_net kernel thread, resulting in a DoS scenario (CVE-2019-3900) A ...
Impact: Important Public Date: 2019-04-25 CWE: CWE-835 Bugzilla: 1698757: CVE-2019-3900 Kernel: vhost_n ...

References

CWE-835https://www.spinics.net/lists/kernel/msg3111012.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3900http://www.securityfocus.com/bid/108076https://security.netapp.com/advisory/ntap-20190517-0005/https://access.redhat.com/errata/RHSA-2019:1973https://access.redhat.com/errata/RHSA-2019:2043https://access.redhat.com/errata/RHSA-2019:2029https://www.debian.org/security/2019/dsa-4497https://seclists.org/bugtraq/2019/Aug/18https://lists.debian.org/debian-lts-announce/2019/08/msg00016.htmlhttps://lists.debian.org/debian-lts-announce/2019/08/msg00017.htmlhttps://usn.ubuntu.com/4114-1/https://usn.ubuntu.com/4117-1/https://usn.ubuntu.com/4116-1/https://usn.ubuntu.com/4115-1/https://usn.ubuntu.com/4118-1/https://access.redhat.com/errata/RHSA-2019:3220https://access.redhat.com/errata/RHSA-2019:3517https://access.redhat.com/errata/RHSA-2019:3309https://seclists.org/bugtraq/2019/Nov/11http://packetstormsecurity.com/files/155212/Slackware-Security-Advisory-Slackware-14.2-kernel-Updates.htmlhttps://access.redhat.com/errata/RHSA-2019:3836https://access.redhat.com/errata/RHSA-2019:3967https://access.redhat.com/errata/RHSA-2019:4058https://access.redhat.com/errata/RHSA-2020:0204https://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RI3WXXM5URTZSR3RVEKO6MDXDFIKTZ5R/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TOFNJA5NNVXQ6AV6KGZB677JIVXAMJHT/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AYTZH6QCNITK7353S6RCRT2PQHZSDPXD/https://nvd.nist.govhttps://www.debian.org/security/2019/dsa-4497https://usn.ubuntu.com/4116-1/