imPC@ndo IT

Tracker / CVE-2019-19922

CVE-2019-19922

Medium 5.5

kernel/sched/fair.c in the Linux kernel before 5.3.9, when cpu.cfs_quota_us is used (e.g., with Kubernetes), allows attackers to cause a denial of service against non-cpu-bound applications by generating a workload that triggers unwanted slice expiration, aka CID-de53fd7aedb1. (In other words, although this slice expiration would typically be seen with benign workloads, it is possible that an attacker could calculate how many stray requests are required to force an entire Kubernetes cluster into a low-performance state caused by slice expiration, and ensure that a DDoS attack sent that number of stray requests. An attack does not affect the stability of the kernel; it only causes mismanagement of application execution.)

Affected products and versions

canonical ubuntu_linux
debian debian_linux
linux linux_kernel · … → 5.3.9
netapp active_iq_unified_manager
netapp aff_baseboard_management_controller
netapp cloud_backup
netapp data_availability_services
netapp e-series_santricity_os_controller · 11.0 → 11.70.2
netapp fas\/aff_baseboard_management_controller
netapp hci_baseboard_management_controller
netapp solidfire_\&_hci_management_node
netapp solidfire_baseboard_management_controller
netapp steelstore_cloud_integrated_storage
oracle sd-wan_edge

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References