CVE-2019-19922
kernel/sched/fair.c in the Linux kernel before 5.3.9, when cpu.cfs_quota_us is used (e.g., with Kubernetes), allows attackers to cause a denial of service against non-cpu-bound applications by generating a workload that triggers unwanted slice…
Does this matter?
Lower severity and a low EPSS score (0.95%). Track it; it rarely justifies an emergency change on its own.
Description
kernel/sched/fair.c in the Linux kernel before 5.3.9, when cpu.cfs_quota_us is used (e.g., with Kubernetes), allows attackers to cause a denial of service against non-cpu-bound applications by generating a workload that triggers unwanted slice expiration, aka CID-de53fd7aedb1. (In other words, although this slice expiration would typically be seen with benign workloads, it is possible that an attacker could calculate how many stray requests are required to force an entire Kubernetes cluster into a low-performance state caused by slice expiration, and ensure that a DDoS attack sent that number of stray requests. An attack does not affect the stability of the kernel; it only causes mismanagement of application execution.)
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.95% probability · 59th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-400
- Affected
- linux/linux kernel · oracle/sd-wan edge · canonical/ubuntu linux · debian/debian linux · netapp/active iq unified manager · netapp/cloud backup · netapp/data availability services · netapp/e-series santricity os controller · netapp/fas\/aff baseboard management controller · netapp/hci baseboard management controller · netapp/solidfire \& hci management node · netapp/steelstore cloud integrated storage · netapp/aff baseboard management controller · netapp/solidfire baseboard management controller
- Source
- cve@mitre.org
References
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.3.9Mailing List, Patch, Vendor Advisory
- https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=de53fd7aedb100f03e5d2231cfce0e4993282425Mailing List, Patch, Vendor Advisory
- https://github.com/kubernetes/kubernetes/issues/67577Issue Tracking, Patch, Third Party Advisory
- https://github.com/torvalds/linux/commit/de53fd7aedb100f03e5d2231cfce0e4993282425Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/01/msg00013.htmlMailing List, Third Party Advisory
- https://relistan.com/the-kernel-may-be-slowing-down-your-appExploit, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20200204-0002/Third Party Advisory
- https://usn.ubuntu.com/4226-1/Third Party Advisory
- https://www.oracle.com/security-alerts/cpuApr2021.htmlPatch, Third Party Advisory
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.3.9Mailing List, Patch, Vendor Advisory
- https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=de53fd7aedb100f03e5d2231cfce0e4993282425Mailing List, Patch, Vendor Advisory
- https://github.com/kubernetes/kubernetes/issues/67577Issue Tracking, Patch, Third Party Advisory
- https://github.com/torvalds/linux/commit/de53fd7aedb100f03e5d2231cfce0e4993282425Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/01/msg00013.htmlMailing List, Third Party Advisory
- https://relistan.com/the-kernel-may-be-slowing-down-your-appExploit, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20200204-0002/Third Party Advisory
- https://usn.ubuntu.com/4226-1/Third Party Advisory
- https://www.oracle.com/security-alerts/cpuApr2021.htmlPatch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.