MEDIUM · 5.5

CVE-2019-19922

kernel/sched/fair.c in the Linux kernel before 5.3.9, when cpu.cfs_quota_us is used (e.g., with Kubernetes), allows attackers to cause a denial of service against non-cpu-bound applications by generat...

Vulnerability Description

kernel/sched/fair.c in the Linux kernel before 5.3.9, when cpu.cfs_quota_us is used (e.g., with Kubernetes), allows attackers to cause a denial of service against non-cpu-bound applications by generating a workload that triggers unwanted slice expiration, aka CID-de53fd7aedb1. (In other words, although this slice expiration would typically be seen with benign workloads, it is possible that an attacker could calculate how many stray requests are required to force an entire Kubernetes cluster into a low-performance state caused by slice expiration, and ensure that a DDoS attack sent that number of stray requests. An attack does not affect the stability of the kernel; it only causes mismanagement of application execution.)

CVSS Score

5.5

MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
LinuxLinux Kernel< 5.3.9
OracleSd-Wan Edge8.2
CanonicalUbuntu Linux18.04
DebianDebian Linux8.0
NetappActive Iq Unified Manager-
NetappCloud Backup-
NetappData Availability Services-
NetappE-Series Santricity Os Controller>= 11.0, <= 11.70.2
NetappFas\/Aff Baseboard Management Controller-
NetappHci Baseboard Management Controllerh610s
NetappSolidfire \& Hci Management Node-
NetappSteelstore Cloud Integrated Storage-
NetappAff Baseboard Management Controllera700
NetappSolidfire Baseboard Management Controller-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-19922?

CVE-2019-19922 is a vulnerability with a CVSS score of 5.5 (MEDIUM). kernel/sched/fair.c in the Linux kernel before 5.3.9, when cpu.cfs_quota_us is used (e.g., with Kubernetes), allows attackers to cause a denial of service against non-cpu-bound applications by generat...

How severe is CVE-2019-19922?

CVE-2019-19922 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-19922?

Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Oracle Sd-Wan Edge, Canonical Ubuntu Linux, Debian Debian Linux, Netapp Active Iq Unified Manager.