VYPR
Medium severity4.7NVD Advisory· Published May 9, 2020· Updated Jun 17, 2026

CVE-2019-20794

CVE-2019-20794

Description

An issue was discovered in the Linux kernel 4.18 through 5.6.11 when unprivileged user namespaces are allowed. A user can create their own PID namespace, and mount a FUSE filesystem. Upon interaction with this FUSE filesystem, if the userspace component is terminated via a kill of the PID namespace's pid 1, it will result in a hung task, and resources being permanently locked up until system reboot. This can result in resource exhaustion.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • Linux/Kernel2 versions
    cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*range: >=4.18,<=5.6.11
    • (no CPE)range: 4.18 - 5.6.11
  • Linux/Linux kerneldescription
  • Fuse/Fusellm-fuzzy

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.