CVE-2019-19922
5.5
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Exploitability: 1.8 / Impact: 3.6
Source: NVD
Description
kernel/sched/fair.c in the Linux kernel before 5.3.9, when cpu.cfs_quota_us is used (e.g., with Kubernetes), allows attackers to cause a denial of service against non-cpu-bound applications by generating a workload that triggers unwanted slice expiration, aka CID-de53fd7aedb1. (In other words, although this slice expiration would typically be seen with benign workloads, it is possible that an attacker could calculate how many stray requests are required to force an entire Kubernetes cluster into a low-performance state caused by slice expiration, and ensure that a DDoS attack sent that number of stray requests. An attack does not affect the stability of the kernel; it only causes mismanagement of application execution.)
Affected (15)
Show all products
Linux: Linux Kernel · Canonical: Ubuntu Linux · Debian: Debian Linux · Oracle: Sd Wan Edge · Netapp: Active Iq Unified Manager, Aff Baseboard Management Controller, Cloud Backup, Data Availability Services, E Series Santricity Os Controller, Fas/aff Baseboard Management Controller, Hci Baseboard Management Controller, Solidfire & Hci Management Node, Solidfire Baseboard Management Controller, Steelstore Cloud Integrated Storage
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.3.9 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 18.04 | |
| Version 8.0 | |
| Version 8.2 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| All versions | |
| Version a700 | |
| All versions | |
| All versions | |
| From 11.0 to 11.70.2 | |
| All versions | |
| Version h610s | |
| All versions | |
| All versions | |
| All versions |
References (18)
Source: cve@mitre.org
Mailing ListPatchVendor Advisory
Source: cve@mitre.org
Mailing ListPatchVendor Advisory
Source: cve@mitre.org
Issue TrackingPatchThird Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
ExploitThird Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Timeline
No history available yet.