oss-sec mailing list archives

CVE-2019-3900 Kernel: vhost_net: infinite loop while receiving packets leads to DoS


From: P J P <ppandit () redhat com>
Date: Thu, 25 Apr 2019 14:39:18 +0530 (IST)

  Hello,

An infinite loop issue was found in the vhost_net kernel module, while handling incoming packets in handle_rx(). It could occur if one end sends packets faster than the other end can process them.

A guest user, maybe remote one, could use this flaw to stall the vhost_net kernel thread, resulting in a DoS scenario.

Upstream patch:
---------------
  -> https://www.spinics.net/lists/kernel/msg3111012.html

This issue was discovered by Jason Wang(CC'd) of Red Hat Inc.
'CVE-2019-3900' assigned by Red Hat Inc.

Thank you.
--
Prasad J Pandit / Red Hat Product Security Team
47AF CE69 3A90 54AA 9045 1053 DD13 3D32 FE5B 041F


Current thread: