First published: Thu Apr 11 2019(Updated: )
An infinite loop issue was found in the vhost_net kernel module in Linux Kernel up to and including v5.1-rc6, while handling incoming packets in handle_rx(). It could occur if one end sends packets faster than the other end can process them. A guest user, maybe remote one, could use this flaw to stall the vhost_net kernel thread, resulting in a DoS scenario.
Credit: secalert@redhat.com secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/kernel | <0:2.6.32-754.24.2.el6 | 0:2.6.32-754.24.2.el6 |
redhat/kernel-rt | <0:3.10.0-1062.rt56.1022.el7 | 0:3.10.0-1062.rt56.1022.el7 |
redhat/kernel-alt | <0:4.14.0-115.10.1.el7a | 0:4.14.0-115.10.1.el7a |
redhat/kernel | <0:3.10.0-1062.el7 | 0:3.10.0-1062.el7 |
redhat/kernel | <0:3.10.0-693.61.1.el7 | 0:3.10.0-693.61.1.el7 |
redhat/kernel | <0:3.10.0-862.44.2.el7 | 0:3.10.0-862.44.2.el7 |
redhat/kernel | <0:3.10.0-957.38.1.el7 | 0:3.10.0-957.38.1.el7 |
redhat/kernel-rt | <0:4.18.0-147.rt24.93.el8 | 0:4.18.0-147.rt24.93.el8 |
redhat/kernel | <0:4.18.0-147.el8 | 0:4.18.0-147.el8 |
redhat/kernel | <0:4.18.0-80.15.1.el8_0 | 0:4.18.0-80.15.1.el8_0 |
ubuntu/linux | <4.15.0-60.67 | 4.15.0-60.67 |
ubuntu/linux | <5.0.0-27.28 | 5.0.0-27.28 |
ubuntu/linux | <5.2~ | 5.2~ |
ubuntu/linux | <4.4.0-161.189 | 4.4.0-161.189 |
ubuntu/linux-aws | <4.15.0-1047.49 | 4.15.0-1047.49 |
ubuntu/linux-aws | <5.0.0-1014.16 | 5.0.0-1014.16 |
ubuntu/linux-aws | <5.2~ | 5.2~ |
ubuntu/linux-aws | <4.4.0-1092.103 | 4.4.0-1092.103 |
ubuntu/linux-aws-5.0 | <5.2~ | 5.2~ |
ubuntu/linux-aws-hwe | <5.2~ | 5.2~ |
ubuntu/linux-aws-hwe | <4.15.0-1047.49~16.04.1 | 4.15.0-1047.49~16.04.1 |
ubuntu/linux-azure | <5.0.0-1018.19~18.04.1 | 5.0.0-1018.19~18.04.1 |
ubuntu/linux-azure | <5.0.0-1018.19 | 5.0.0-1018.19 |
ubuntu/linux-azure | <5.2~ | 5.2~ |
ubuntu/linux-azure | <4.15.0-1056.61 | 4.15.0-1056.61 |
ubuntu/linux-azure-5.3 | <5.2~ | 5.2~ |
ubuntu/linux-azure-edge | <5.0.0-1018.19~18.04.1 | 5.0.0-1018.19~18.04.1 |
ubuntu/linux-azure-edge | <5.2~ | 5.2~ |
ubuntu/linux-azure-edge | <4.15.0-1056.61 | 4.15.0-1056.61 |
ubuntu/linux-euclid | <5.2~ | 5.2~ |
ubuntu/linux-flo | <5.2~ | 5.2~ |
ubuntu/linux-gcp | <4.15.0-1042.45 | 4.15.0-1042.45 |
ubuntu/linux-gcp | <5.0.0-1015.15 | 5.0.0-1015.15 |
ubuntu/linux-gcp | <5.2~ | 5.2~ |
ubuntu/linux-gcp | <4.15.0-1041.43 | 4.15.0-1041.43 |
ubuntu/linux-gcp-5.3 | <5.2~ | 5.2~ |
ubuntu/linux-gcp-edge | <4.15.0-1042.45 | 4.15.0-1042.45 |
ubuntu/linux-gcp-edge | <5.2~ | 5.2~ |
ubuntu/linux-gke | <5.2~ | 5.2~ |
ubuntu/linux-gke-4.15 | <4.15.0-1041.43 | 4.15.0-1041.43 |
ubuntu/linux-gke-4.15 | <5.2~ | 5.2~ |
ubuntu/linux-gke-5.0 | <5.0.0-1015.15~18.04.1 | 5.0.0-1015.15~18.04.1 |
ubuntu/linux-gke-5.0 | <5.2~ | 5.2~ |
ubuntu/linux-goldfish | <5.2~ | 5.2~ |
ubuntu/linux-grouper | <5.2~ | 5.2~ |
ubuntu/linux-hwe | <5.0.0-27.28~18.04.1 | 5.0.0-27.28~18.04.1 |
ubuntu/linux-hwe | <5.2~ | 5.2~ |
ubuntu/linux-hwe | <4.15.0-60.67~16.04.1 | 4.15.0-60.67~16.04.1 |
ubuntu/linux-hwe-edge | <5.2~ | 5.2~ |
ubuntu/linux-hwe-edge | <4.15.0-60.67~16.04.1 | 4.15.0-60.67~16.04.1 |
ubuntu/linux-kvm | <4.15.0-1043.43 | 4.15.0-1043.43 |
ubuntu/linux-kvm | <5.0.0-1015.16 | 5.0.0-1015.16 |
ubuntu/linux-kvm | <5.2~ | 5.2~ |
ubuntu/linux-kvm | <4.4.0-1056.63 | 4.4.0-1056.63 |
ubuntu/linux-lts-trusty | <5.2~ | 5.2~ |
ubuntu/linux-lts-utopic | <5.2~ | 5.2~ |
ubuntu/linux-lts-vivid | <5.2~ | 5.2~ |
ubuntu/linux-lts-wily | <5.2~ | 5.2~ |
ubuntu/linux-lts-xenial | <5.2~ | 5.2~ |
ubuntu/linux-maguro | <5.2~ | 5.2~ |
ubuntu/linux-mako | <5.2~ | 5.2~ |
ubuntu/linux-manta | <5.2~ | 5.2~ |
ubuntu/linux-oem | <4.15.0-1056.65 | 4.15.0-1056.65 |
ubuntu/linux-oem | <4.15.0-1059.68 | 4.15.0-1059.68 |
ubuntu/linux-oem | <5.2~ | 5.2~ |
ubuntu/linux-oem-5.4 | <5.2~ | 5.2~ |
ubuntu/linux-oem-osp1 | <5.0.0-1020.22 | 5.0.0-1020.22 |
ubuntu/linux-oem-osp1 | <5.0.0-1022.24 | 5.0.0-1022.24 |
ubuntu/linux-oem-osp1 | <5.2~ | 5.2~ |
ubuntu/linux-oracle | <4.15.0-1022.25 | 4.15.0-1022.25 |
ubuntu/linux-oracle | <5.0.0-1004.8 | 5.0.0-1004.8 |
ubuntu/linux-oracle | <5.2~ | 5.2~ |
ubuntu/linux-oracle | <4.15.0-1022.25~16.04.1 | 4.15.0-1022.25~16.04.1 |
ubuntu/linux-oracle-5.0 | <5.2~ | 5.2~ |
ubuntu/linux-raspi2 | <4.15.0-1044.47 | 4.15.0-1044.47 |
ubuntu/linux-raspi2 | <5.0.0-1015.15 | 5.0.0-1015.15 |
ubuntu/linux-raspi2 | <5.2~ | 5.2~ |
ubuntu/linux-raspi2 | <4.4.0-1120.129 | 4.4.0-1120.129 |
ubuntu/linux-raspi2-5.3 | <5.2~ | 5.2~ |
ubuntu/linux-snapdragon | <4.15.0-1062.69 | 4.15.0-1062.69 |
ubuntu/linux-snapdragon | <5.0.0-1019.20 | 5.0.0-1019.20 |
ubuntu/linux-snapdragon | <5.2~ | 5.2~ |
ubuntu/linux-snapdragon | <4.4.0-1124.130 | 4.4.0-1124.130 |
Linux Linux kernel | <5.1 | |
Linux Linux kernel | =5.1-rc1 | |
Linux Linux kernel | =5.1-rc2 | |
Linux Linux kernel | =5.1-rc3 | |
Linux Linux kernel | =5.1-rc4 | |
Linux Linux kernel | =5.1-rc5 | |
Linux Linux kernel | =5.1-rc6 | |
Fedoraproject Fedora | =29 | |
Fedoraproject Fedora | =30 | |
Redhat Enterprise Linux | =6.0 | |
Redhat Enterprise Linux | =7.0 | |
Debian Debian Linux | =8.0 | |
Debian Debian Linux | =9.0 | |
Debian Debian Linux | =10.0 | |
Canonical Ubuntu Linux | =16.04 | |
Canonical Ubuntu Linux | =18.04 | |
Canonical Ubuntu Linux | =19.04 | |
Netapp Active Iq Unified Manager For Vmware Vsphere | >=9.5 | |
Netapp Hci Management Node | ||
Netapp Snapprotect | ||
Netapp Solidfire | ||
Netapp Storage Replication Adapter For Clustered Data Ontap For Vmware Vsphere | >=7.2 | |
Netapp Vasa Provider For Clustered Data Ontap | >=7.2 | |
NetApp Virtual Storage Console for VMware vSphere | >=7.2 | |
Netapp Cn1610 Firmware | ||
Netapp Cn1610 | ||
Oracle SD-WAN Edge | =8.2 | |
Linux Linux kernel | >=2.6.34<3.16.72 | |
Linux Linux kernel | >=3.17<4.4.191 | |
Linux Linux kernel | >=4.5<4.9.190 | |
Linux Linux kernel | >=4.10<4.14.133 | |
Linux Linux kernel | >=4.15<4.19.64 | |
Linux Linux kernel | >=4.20<5.2 | |
All of | ||
Netapp Cn1610 Firmware | ||
Netapp Cn1610 | ||
Fedoraproject Fedora | =28 | |
debian/linux | 5.10.218-1 6.1.94-1 6.1.90-1 6.8.12-1 6.9.7-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)