CVE-2019-19922
Vulnerability Summary
Timeline
Description
kernel/sched/fair.c in the Linux kernel before 5.3.9, when cpu.cfs_quota_us is used (e.g., with Kubernetes), allows attackers to cause a denial of service against non-cpu-bound applications by generating a workload that triggers unwanted slice expiration, aka CID-de53fd7aedb1. (In other words, although this slice expiration would typically be seen with benign workloads, it is possible that an attacker could calculate how many stray requests are required to force an entire Kubernetes cluster into a low-performance state caused by slice expiration, and ensure that a DDoS attack sent that number of stray requests. An attack does not affect the stability of the kernel; it only causes mismanagement of application execution.)
CVSS Metrics
- v3.1•MEDIUM•Score: 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- v2.0•LOW•Score: 2.1AV:L/AC:L/Au:N/C:N/I:N/A:P
EPSS Trends
Current EPSS score: 0.11%• Percentile: 28%
Techniques & Countermeasures
- CWE-400•Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource.
Affected Systems
- canonical•ubuntu_linux
18.04 | 19.04
- debian•debian_linux
8.0
- linux•linux_kernel
< 5.3.9
- netapp•active_iq_unified_manager
na
- netapp•aff_baseboard_management_controller
a700
- netapp•cloud_backup
na
- netapp•data_availability_services
na
- netapp•e-series_santricity_os_controller
≥ 11.0, ≤ 11.70.2
- netapp•fas\/aff_baseboard_management_controller
na
- netapp•hci_baseboard_management_controller
h610s
- netapp•solidfire_\&_hci_management_node
na
- netapp•solidfire_baseboard_management_controller_firmware
na
- netapp•steelstore_cloud_integrated_storage
na
- oracle•sd-wan_edge
8.2
References (9)
- https://usn.ubuntu.com/4226-1/
- https://lists.debian.org/debian-lts-announce/2020/01/msg00013.html
- https://www.oracle.com/security-alerts/cpuApr2021.html
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.3.9
- https://github.com/torvalds/linux/commit/de53fd7aedb100f03e5d2231cfce0e4993282425
- https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=de53fd7aedb100f03e5d2231cfce0e4993282425
- https://relistan.com/the-kernel-may-be-slowing-down-your-app
- https://github.com/kubernetes/kubernetes/issues/67577
- https://security.netapp.com/advisory/ntap-20200204-0002/