CVE-2019-20794
⚪ Do wiadomości
Błąd w jądrze Linux umożliwia zablokowanie zasobów przez nieuprzywilejowanego użytkownika.
CVSS
4.7
EPSS
0.5%
Exploit
poc
Vendor
linux
Opis źródłowy (NVD)
An issue was discovered in the Linux kernel 4.18 through 5.6.11 when unprivileged user namespaces are allowed. A user can create their own PID namespace, and mount a FUSE filesystem. Upon interaction with this FUSE filesystem, if the userspace component is terminated via a kill of the PID namespace's pid 1, it will result in a hung task, and resources being permanently locked up until system reboot. This can result in resource exhaustion.
dos exploit
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 4.7 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.5% |
| Opublikowano (NVD) | 2020-05-09 18:15:11 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-08 21:17:19 UTC |
Referencje
- http://www.openwall.com/lists/oss-security/2020/08/24/1 ([email protected]) [Mailing List, Third Party Advisory]
- https://github.com/sargun/fuse-example ([email protected]) [Exploit, Third Party Advisory]
- https://security.netapp.com/advisory/ntap-20200608-0001/ ([email protected]) [Third Party Advisory]
- https://sourceforge.net/p/fuse/mailman/message/36598753/ ([email protected]) [Exploit, Third Party Advisory]