imPC@ndo IT

Tracker / CVE-2019-3874

CVE-2019-3874

Medium 6.5

The SCTP socket buffer used by a userspace application is not accounted by the cgroups subsystem. An attacker can use this flaw to cause a denial of service attack. Kernel 3.10.x and 4.18.x branches are believed to be vulnerable.

Affected products and versions

canonical ubuntu_linux
debian debian_linux
linux linux_kernel · 3.10.1 → 3.10.108
linux linux_kernel · 4.18.1 → 4.18.20
netapp active_iq_unified_manager_for_vmware_vsphere · 9.5 → …
netapp cn1610_firmware
netapp hci_management_node
netapp snapprotect
netapp solidfire
redhat enterprise_linux

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References