Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-19922


kernel/sched/fair.c in the Linux kernel before 5.3.9, when cpu.cfs_quota_us is used (e.g., with Kubernetes), allows attackers to cause a denial of service against non-cpu-bound applications by generating a workload that triggers unwanted slice expiration, aka CID-de53fd7aedb1. (In other words, although this slice expiration would typically be seen with benign workloads, it is possible that an attacker could calculate how many stray requests are required to force an entire Kubernetes cluster into a low-performance state caused by slice expiration, and ensure that a DDoS attack sent that number of stray requests. An attack does not affect the stability of the kernel; it only causes mismanagement of application execution.)


Published

2019-12-22T20:15:10.823

Last Modified

2024-11-21T04:35:40.277

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.5 (MEDIUM)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:N/I:N/A:P

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

3.9

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-400

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System linux linux_kernel < 5.3.9 Yes
Application oracle sd-wan_edge 8.2 Yes
Operating System canonical ubuntu_linux 18.04 Yes
Operating System canonical ubuntu_linux 19.04 Yes
Operating System debian debian_linux 8.0 Yes
Application netapp active_iq_unified_manager - Yes
Application netapp cloud_backup - Yes
Application netapp data_availability_services - Yes
Application netapp e-series_santricity_os_controller ≤ 11.70.2 Yes
Application netapp fas\/aff_baseboard_management_controller - Yes
Application netapp hci_baseboard_management_controller h610s Yes
Application netapp solidfire_\&_hci_management_node - Yes
Application netapp steelstore_cloud_integrated_storage - Yes
Hardware netapp aff_baseboard_management_controller a700 Yes
Hardware netapp solidfire_baseboard_management_controller - Yes

References