Bug 1171737 - (CVE-2019-20794) VUL-1: CVE-2019-20794: kernel-source: An issue was discovered when unprivileged user namespaces are allowed
(CVE-2019-20794)
VUL-1: CVE-2019-20794: kernel-source: An issue was discovered when unprivileg...
Status: NEW
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P4 - Low : Minor
: ---
Assigned To: Security Team bot
Security Team bot
https://smash.suse.de/issue/259355/
CVSSv3.1:SUSE:CVE-2019-20794:4.7:(AV:...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2020-05-15 13:02 UTC by Robert Frohl
Modified: 2020-09-01 09:51 UTC (History)
7 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Robert Frohl 2020-05-15 13:02:09 UTC
CVE-2019-20794

An issue was discovered in the Linux kernel 4.18 through 5.6.11 when
unprivileged user namespaces are allowed. A user can create their own PID
namespace, and mount a FUSE filesystem. Upon interaction with this FUSE
filesystem, if the userspace component is terminated via a kill of the PID
namespace's pid 1, it will result in a hung task, and resources being
permanently locked up until system reboot. This can result in resource
exhaustion.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-20794
http://people.canonical.com/~ubuntu-security/cve/2019/CVE-2019-20794.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-20794
https://github.com/sargun/fuse-example
https://sourceforge.net/p/fuse/mailman/message/36598753/