CVE-2019-3900: Canonical Ubuntu Linux
High severity, CVSS 7.7. EPSS: 4.3% chance of exploitation in the next 30 days.
An infinite loop issue was found in the vhost_net kernel module in Linux Kernel up to and including v5.1-rc6, while handling incoming packets in handle_rx(). It could occur if one end sends packets faster than the other end can process them. A guest user, maybe remote one, could use this flaw to stall the vhost_net kernel thread, resulting in a DoS scenario.
Affected products
- Canonical Ubuntu Linux: version 16.04 only; version 18.04 only; version 19.04 only
- Debian Debian Linux: version 8.0 only; version 9.0 only; version 10.0 only
- Fedoraproject Fedora: version 29 only; version 30 only; version 28 only
- Linux Linux Kernel: from 2.6.34, before 3.16.72 (fixed in 3.16.72); from 3.17, before 4.4.191 (fixed in 4.4.191); from 4.5, before 4.9.190 (fixed in 4.9.190); from 4.10, before 4.14.133 (fixed in 4.14.133); from 4.15, before 4.19.64 (fixed in 4.19.64); from 4.20, before 5.2 (fixed in 5.2)
- Netapp Active Iq Unified Manager For VMware Vsphere: from 9.5
- Netapp CN1610 Firmware: affected versions not specified
- Netapp Hci Management Node: affected versions not specified
- Netapp Snapprotect: affected versions not specified
- Netapp Solidfire: affected versions not specified
- Netapp Storage Replication Adapter For Clustered Data Ontap For VMware Vsphere: from 7.2
- Netapp Vasa Provider For Clustered Data Ontap: from 7.2
- Netapp Virtual Storage Console For VMware Vsphere: from 7.2
- Oracle SD-WAN Edge: version 8.2 only
- Red Hat Enterprise Linux: version 6.0 only; version 7.0 only
Published 2019-04-25. Last modified 2026-06-17.