An issue was discovered in the Linux kernel 4.18 through 5.6.11 when unprivileged user namespaces are allowed. A user can create their own PID namespace, and mount a FUSE filesystem. Upon interaction with this FUSE filesystem, if the userspace component is terminated via a kill of the PID namespace's pid 1, it will result in a hung task, and resources being permanently locked up until system reboot. This can result in resource exhaustion.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2020-05-09T17:35:50
Updated: 2024-08-05T02:53:09.326Z
Reserved: 2020-05-09T00:00:00
Link: CVE-2019-20794
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-05-09T18:15:11.157
Modified: 2024-11-21T04:39:22.780
Link: CVE-2019-20794
Redhat