Bug 1849005 (CVE-2019-20794) - CVE-2019-20794 kernel: task processes not being properly ended could lead to resource exhaustion
Summary: CVE-2019-20794 kernel: task processes not being properly ended could lead to ...
Keywords:
Status: NEW
Alias: CVE-2019-20794
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Nobody
QA Contact:
URL:
Whiteboard:
Depends On: 1849006 1867711 1867712 1867713 1867714 1867715 1911196
Blocks: 1849008
TreeView+ depends on / blocked
 
Reported: 2020-06-19 13:09 UTC by Marian Rehak
Modified: 2024-01-19 19:10 UTC (History)
40 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
A flaw was found in the Linux kernel. A user with PID namespace mounting a FUSE filesystem could cause a denial of service if the userspace component is terminated (pid 1). The highest threat from this vulnerability is to system availability.
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Marian Rehak 2020-06-19 13:09:23 UTC
A flaw was found when a user with PID namespace mounting a FUSE filesystem, If the userspace component is terminated (pid 1), this results into a denial of service (DoS) problem. This internally makes the fuse requests go into Uninterruptiblein state until the system is rebooted.

Reference:

https://github.com/sargun/fuse-example

Comment 1 Marian Rehak 2020-06-19 13:10:12 UTC
Created kernel tracking bugs for this issue:

Affects: fedora-all [bug 1849006]


Note You need to log in before you can comment on or make changes to this bug.