Beveiligingsadvies

CVE-2019-3837

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2019-04-11 14:37:26
Laatst bijgewerkt 2024-08-04 19:19:18
Toegewezen door redhat
CVSS-score 6.1
Status PUBLISHED

Beschrijving

It was found that the net_dma code in tcp_recvmsg() in the 2.6.32 kernel as shipped in RHEL6 is thread-unsafe. So an unprivileged multi-threaded userspace application calling recvmsg() for the same network socket in parallel executed on ioatdma-enabled hardware with net_dma enabled can leak the memory, crash the host leading to a denial-of-service or cause a random memory corruption.