CVE-2019-3837 describes a thread-unsafe condition in the net_dma code within the tcp_recvmsg() function of the Linux kernel (specifically 2.6.32 as shipped in RHEL6). This vulnerability affects Red Hat Enterprise Linux and the Linux kernel. A local, unprivileged attacker can exploit this flaw by running a multi-threaded application that calls recvmsg() on the same network socket in parallel on systems with ioatdma-enabled hardware and net_dma enabled. This can lead to memory leaks, host crashes (Denial of Service), or random memory corruption. The CVSS score is 6.1 (Medium), indicating a low attack complexity and requiring local user privileges. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.6.32CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6.32:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.