CVE-2019-20794 PUBLISHED

An issue was discovered in the Linux kernel 4.18 through 5.6.11 when unprivileged user namespaces are allowed. A user can create their own PID namespace, and mount a FUSE filesystem. Upon interaction with this FUSE filesystem, if the userspace component is terminated via a kill of the PID namespace's pid 1, it will result in a hung task, and resources being permanently locked up until system reboot. This can result in resource exhaustion.

EPSS 0.09% · 26.1th percentile

Risk Scores

EPSS Score
0.09%
26.1th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSlinux-azure-edge4.18.0-1008.8~18.04.1, 4.18.0-1007.7~18.04.1, 4.18.0-1006.6~18.04.1
Ubuntu:Pro:18.04:LTSlinux-gcp-5.45.4.0-1122.131~18.04.1, 5.4.0-1121.130~18.04.1, 5.4.0-1120.129~18.04.1
Ubuntu:Pro:18.04:LTSlinux4.15.0-184.194, 4.15.0-246.258, 4.15.0-245.257
Ubuntu:Pro:18.04:LTSlinux-oracle-5.45.4.0-1143.153~18.04.1, 5.4.0-1142.152~18.04.1, 5.4.0-1141.151~18.04.1
Ubuntu:Pro:20.04:LTSlinux-riscv-5.155.15.0-1090.94~20.04.1, 5.15.0-1087.91~20.04.1, 5.15.0-1086.90~20.04.1
Ubuntu:Pro:FIPS:20.04:LTSlinux-aws-fips5.4.0-1021.21+fips2, 0
Ubuntu:20.04:LTSlinux-azure-fde5.4.0-1074.77+cvm1.1, 5.4.0-1076.79+cvm1.1, 5.4.0-1078.81+cvm1.1
Ubuntu:24.04:LTSlinux-oem-6.146.14.0-1007.7, 6.14.0-1006.6, 6.14.0-1019.19
Ubuntu:Pro:18.04:LTSlinux-hwe-5.45.4.0-105.119~18.04.1, 5.4.0-225.245~18.04.1, 5.4.0-224.244~18.04.1
Ubuntu:22.04:LTSlinux5.15.0-30.31, 5.15.0-27.28, 5.15.0-25.25
Ubuntu:25.10linux-gcp6.17.0-1007.7, 6.17.0-1006.6, 6.17.0-1005.5
Ubuntu:22.04:LTSlinux-riscv-5.195.19.0-1019.21~22.04.1, 5.19.0-1021.23~22.04.1, 5.19.0-1020.22~22.04.1
Ubuntu:24.04:LTSlinux-riscv6.8.0-36.36.1, 6.8.0-38.38.1, 6.8.0-39.39.1
Ubuntu:22.04:LTSlinux-oem-6.56.5.0-1013.14, 0, 6.5.0-1003.3
Ubuntu:22.04:LTSlinux-gkeop5.15.0-1069.77, 5.15.0-1070.78, 5.15.0-1071.79
Ubuntu:Pro:20.04:LTSlinux-nvidia-tegra-5.155.15.0-1053.53~20.04.1, 5.15.0-1052.52~20.04.2, 5.15.0-1051.51~20.04.1
Ubuntu:Pro:FIPS:16.04:LTSlinux-fips4.4.0-1063.69, 4.4.0-1064.70, 4.4.0-1065.71
Ubuntu:24.04:LTSlinux-gcp-6.116.11.0-1006.6~24.04.2, 6.11.0-1013.13~24.04.1, 0
Ubuntu:18.04:LTSlinux-hwe4.18.0-16.17~18.04.1, 4.18.0-17.18~18.04.1, 4.18.0-18.19~18.04.1
Ubuntu:Pro:20.04:LTSlinux-gcp5.4.0-1127.136, 5.4.0-1125.134, 5.4.0-1124.133

…and 219 more

Timeline

References

Open in Interactive Console →