CVE-2019-19922

Advisory lineage Upstream: 0 Downstream: 7
Modified
Published: 22 Dec 2019, 19:07
Last modified:05 Aug 2024, 02:32

Vulnerability Summary

Overall Risk (default)
medium
32/100
CVSS Score
5.5 MEDIUM
v3.1 (nvd)
EPSS Score
0.11% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

22 Dec 2019, 19:07
Published
Vulnerability first disclosed
05 Aug 2024, 02:32
Last Modified
Vulnerability information updated

Description

kernel/sched/fair.c in the Linux kernel before 5.3.9, when cpu.cfs_quota_us is used (e.g., with Kubernetes), allows attackers to cause a denial of service against non-cpu-bound applications by generating a workload that triggers unwanted slice expiration, aka CID-de53fd7aedb1. (In other words, although this slice expiration would typically be seen with benign workloads, it is possible that an attacker could calculate how many stray requests are required to force an entire Kubernetes cluster into a low-performance state caused by slice expiration, and ensure that a DDoS attack sent that number of stray requests. An attack does not affect the stability of the kernel; it only causes mismanagement of application execution.)

CVSS Metrics

  • v3.1MEDIUMScore: 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
  • v2.0LOWScore: 2.1AV:L/AC:L/Au:N/C:N/I:N/A:P

EPSS Trends

Current EPSS score: 0.11% Percentile: 28%

Techniques & Countermeasures

  • CWE-400Uncontrolled Resource Consumption

    The product does not properly control the allocation and maintenance of a limited resource.

Affected Systems

  • canonicalubuntu_linux

    18.04 | 19.04

  • debiandebian_linux

    8.0

  • linuxlinux_kernel

    < 5.3.9

  • netappactive_iq_unified_manager

    na

  • netappaff_baseboard_management_controller

    a700

  • netappcloud_backup

    na

  • netappdata_availability_services

    na

  • netappe-series_santricity_os_controller

    ≥ 11.0, ≤ 11.70.2

  • netappfas\/aff_baseboard_management_controller

    na

  • netapphci_baseboard_management_controller

    h610s

  • netappsolidfire_\&_hci_management_node

    na

  • netappsolidfire_baseboard_management_controller_firmware

    na

  • netappsteelstore_cloud_integrated_storage

    na

  • oraclesd-wan_edge

    8.2

References (9)