CVE-2019-3874
Vulnerability Summary
Timeline
Description
The SCTP socket buffer used by a userspace application is not accounted by the cgroups subsystem. An attacker can use this flaw to cause a denial of service attack. Kernel 3.10.x and 4.18.x branches are believed to be vulnerable.
CVSS Metrics
- v3.1•MEDIUM•Score: 6.5CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- v3.0•MEDIUM•Score: 5.3CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
- v3.0•MEDIUM•Score: 6.5CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- v2.0•LOW•Score: 3.3AV:A/AC:L/Au:N/C:N/I:N/A:P
EPSS Trends
Current EPSS score: 1.77%• Percentile: 77%
Techniques & Countermeasures
- CWE-400•Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource.
Affected Systems
- canonical•ubuntu_linux
14.04 | 16.04 | 18.04 | 18.10 | 19.04
- debian•linux
< 5.2.6-1 | < 5.2.6-1 | < 5.2.6-1 | < 5.2.6-1
- ubuntu•linux
all | < 4.4.0-148.174 | < 4.15.0-50.54
- ubuntu•linux-aws
< 4.4.0-1044.47 | < 4.4.0-1083.93 | < 4.15.0-1039.41
- ubuntu•linux-aws-hwe
< 4.15.0-1039.41~16.04.1
- ubuntu•linux-azure
< 4.15.0-1045.49~14.04.1 | < 4.15.0-1045.49 | < 4.18.0-1018.18~18.04.1
- ubuntu•linux-azure-6.11
all
- ubuntu•linux-azure-fde
all
- ubuntu•linux-azure-fde-5.15
all
- ubuntu•linux-fips
< 4.4.0-1010.13
- ubuntu•linux-gcp
< 4.15.0-1032.34~16.04.1 | < 4.15.0-1032.34
- ubuntu•linux-gcp-6.11
all
- ubuntu•linux-gcp-edge
< 4.18.0-1011.12~18.04.1
- ubuntu•linux-gke
all
- ubuntu•linux-gke-4.15
< 4.15.0-1032.34
- ubuntu•linux-hwe
< 4.15.0-50.54~16.04.1 | < 4.18.0-20.21~18.04.1
- ubuntu•linux-hwe-6.11
all
- ubuntu•linux-intel-iot-realtime
all
- ubuntu•linux-kvm
< 4.4.0-1046.52 | < 4.15.0-1034.34
- ubuntu•linux-lowlatency-hwe-6.11
all
- ubuntu•linux-lts-xenial
< 4.4.0-148.174~14.04.1
- ubuntu•linux-oem
< 4.15.0-1038.43
- ubuntu•linux-oracle
< 4.15.0-1013.15~16.04.1 | < 4.15.0-1013.15
- ubuntu•linux-raspi-realtime
all
- ubuntu•linux-raspi2
< 4.4.0-1109.117 | < 4.15.0-1036.38 | all
- ubuntu•linux-realtime
all
- ubuntu•linux-riscv
all | all
- ubuntu•linux-snapdragon
< 4.4.0-1113.118 | < 4.15.0-1053.57
- debian•debian_linux
8.0
- linux•linux_kernel
≥ 3.10.1, ≤ 3.10.108 | ≥ 4.18.1, ≤ 4.18.20
- netapp•active_iq_unified_manager_for_vmware_vsphere
≥ 9.5
- netapp•cn1610_firmware
na
- netapp•hci_management_node
na
- netapp•snapprotect
na
- netapp•solidfire
na
- redhat•enterprise_linux
7.0
- the linux foundation•kernel
3.10.x and 4.18.x
References (26)
- https://usn.ubuntu.com/3981-1/
- https://usn.ubuntu.com/3980-1/
- https://usn.ubuntu.com/3979-1/
- https://usn.ubuntu.com/3982-2/
- https://usn.ubuntu.com/3982-1/
- https://usn.ubuntu.com/3980-2/
- https://usn.ubuntu.com/3981-2/
- https://access.redhat.com/errata/RHSA-2019:3309
- https://access.redhat.com/errata/RHSA-2019:3517
- https://lists.debian.org/debian-lts-announce/2020/09/msg00025.html
- https://www.oracle.com/security-alerts/cpuApr2021.html
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3874
- https://security.netapp.com/advisory/ntap-20190411-0003/
- https://ubuntu.com/security/CVE-2019-3874
- https://lore.kernel.org/netdev/cover.1554022192.git.lucien.xin@gmail.com/
- https://git.kernel.org/pub/scm/linux/kernel/git/davem/net-next.git/commit/?id=1033990ac5b2ab6cee93734cb6d301aa3a35bcaa
- https://git.kernel.org/pub/scm/linux/kernel/git/davem/net-next.git/commit/?id=9dde27de3e5efa0d032f3c891a0ca833a0d31911
- https://ubuntu.com/security/notices/USN-3979-1
- https://ubuntu.com/security/notices/USN-3980-1
- https://ubuntu.com/security/notices/USN-3981-1
- https://ubuntu.com/security/notices/USN-3982-1
- https://ubuntu.com/security/notices/USN-3982-2
- https://ubuntu.com/security/notices/USN-3980-2
- https://ubuntu.com/security/notices/USN-3981-2
- https://www.cve.org/CVERecord?id=CVE-2019-3874
- https://security-tracker.debian.org/tracker/CVE-2019-3874