VDB

CVE-2019-20794

CVE-2019-20794 PUBLISHED

An issue was discovered in the Linux kernel 4.18 through 5.6.11 when unprivileged user namespaces are allowed. A user can create their own PID namespace, and mount a FUSE filesystem. Upon interaction with this FUSE filesystem, if the userspace component is terminated via a kill of the PID namespace's pid 1, it will result in a hung task, and resources being permanently locked up until system reboot. This can result in resource exhaustion.

EPSS 0.09% · 26.2th percentile

Risk Scores

EPSS Score
0.09%
26.2th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSlinux-azure-edge4.18.0-1006.6~18.04.1, 4.18.0-1007.7~18.04.1, 4.18.0-1008.8~18.04.1
Ubuntu:Pro:18.04:LTSlinux-gcp-5.45.4.0-1030.32~18.04.1, 5.4.0-1032.34~18.04.1, 5.4.0-1034.37~18.04.1
Ubuntu:Pro:18.04:LTSlinux4.15.0-65.74, 4.15.0-64.73, 4.15.0-62.69
Ubuntu:Pro:18.04:LTSlinux-oracle-5.45.4.0-1101.110~18.04.1, 5.4.0-1100.109~18.04.1, 5.4.0-1099.108~18.04.1
Ubuntu:Pro:20.04:LTSlinux-riscv-5.155.15.0-1068.72~20.04.1, *, *
Ubuntu:Pro:FIPS:20.04:LTSlinux-aws-fips5.4.0-1021.21+fips2, 0
Ubuntu:20.04:LTSlinux-azure-fde5.4.0-1103.109+cvm1.1, 5.4.0-1076.79+cvm1.1, 5.4.0-1080.83+cvm1.1
Ubuntu:24.04:LTSlinux-oem-6.146.14.0-1007.7, 6.14.0-1014.14, 6.14.0-1016.16
Ubuntu:Pro:18.04:LTSlinux-hwe-5.45.4.0-105.119~18.04.1, *, *
Ubuntu:22.04:LTSlinux5.15.0-56.62, 0, 5.13.0-19.19
Ubuntu:25.10linux-gcp6.17.0-1001.1, 6.17.0-1002.2, 6.17.0-1003.3
Ubuntu:22.04:LTSlinux-riscv-5.19*, 5.19.0-1019.21~22.04.1, 5.19.0-1018.19~22.04.1
Ubuntu:24.04:LTSlinux-riscv6.8.0-55.57.1, 6.8.0-57.59.1, 6.8.0-58.60.1
Ubuntu:22.04:LTSlinux-oem-6.56.5.0-1004.4, 6.5.0-1023.24, 0
Ubuntu:22.04:LTSlinux-gkeop5.15.0-1064.72, 5.15.0-1065.73, 5.15.0-1058.66
Ubuntu:Pro:20.04:LTSlinux-nvidia-tegra-5.155.15.0-1051.51~20.04.1, 5.15.0-1050.50~20.04.1, 5.15.0-1049.49~20.04.1
Ubuntu:Pro:FIPS:16.04:LTSlinux-fips4.4.0-1060.66, 4.4.0-1063.69, 4.4.0-1065.71
Ubuntu:24.04:LTSlinux-gcp-6.116.11.0-1017.17~24.04.1, *, 0
Ubuntu:18.04:LTSlinux-hwe4.18.0-14.15~18.04.1, 4.18.0-13.14~18.04.1, 0
Ubuntu:Pro:20.04:LTSlinux-gcp5.4.0-1075.80, 5.4.0-1041.44, 5.4.0-1151.160

…and 219 more

Timeline

  • May 9, 2020 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Oct 26, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Feb 28, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • May 1, 2022 EPSS Score
  • Jul 3, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›