---
id: CVE-2019-20794
title: >-
  An issue was discovered in the Linux kernel 4.18 through 5.6.11 when
  unprivileged user namespaces are allowed
summary: >-
  An issue was discovered in the Linux kernel 4.18 through 5.6.11 when
  unprivileged user namespaces are allowed. A user can create their own PID
  namespace, and mount a FUSE filesystem. Upon interaction with this FUSE
  filesystem, if the use…
severity: medium
cvss: 4.7
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-772
vendor: linux
product: linux_kernel
affected:
  - 'linux_kernel >= 4.18, <= 5.6.11'
published: '2020-05-09'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T21:17:19.947'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2019-20794'
references:
  - url: 'http://www.openwall.com/lists/oss-security/2020/08/24/1'
    label: cve@mitre.org
  - url: 'https://github.com/sargun/fuse-example'
    label: cve@mitre.org
  - url: 'https://security.netapp.com/advisory/ntap-20200608-0001/'
    label: cve@mitre.org
  - url: 'https://sourceforge.net/p/fuse/mailman/message/36598753/'
    label: cve@mitre.org
  - url: 'http://www.openwall.com/lists/oss-security/2020/08/24/1'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://github.com/sargun/fuse-example'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20200608-0001/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://sourceforge.net/p/fuse/mailman/message/36598753/'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00512
epssPercentile: 0.41794
ingestedAt: '2026-10-08T22:11:53.714Z'
---

## Overview

An issue was discovered in the Linux kernel 4.18 through 5.6.11 when unprivileged user namespaces are allowed. A user can create their own PID namespace, and mount a FUSE filesystem. Upon interaction with this FUSE filesystem, if the userspace component is terminated via a kill of the PID namespace's pid 1, it will result in a hung task, and resources being permanently locked up until system reboot. This can result in resource exhaustion.

## Affected

- `linux_kernel >= 4.18, <= 5.6.11`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
