Description
kernel/sched/fair.c in the Linux kernel before 5.3.9, when cpu.cfs_quota_us is used (e.g., with Kubernetes), allows attackers to cause a denial of service against non-cpu-bound applications by generating a workload that triggers unwanted slice expiration, aka CID-de53fd7aedb1. (In other words, although this slice expiration would typically be seen with benign workloads, it is possible that an attacker could calculate how many stray requests are required to force an entire Kubernetes cluster into a low-performance state caused by slice expiration, and ensure that a DDoS attack sent that number of stray requests. An attack does not affect the stability of the kernel; it only causes mismanagement of application execution.)
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2068-1 | linux security update |
EUVD |
EUVD-2019-9511 | kernel/sched/fair.c in the Linux kernel before 5.3.9, when cpu.cfs_quota_us is used (e.g., with Kubernetes), allows attackers to cause a denial of service against non-cpu-bound applications by generating a workload that triggers unwanted slice expiration, aka CID-de53fd7aedb1. (In other words, although this slice expiration would typically be seen with benign workloads, it is possible that an attacker could calculate how many stray requests are required to force an entire Kubernetes cluster into a low-performance state caused by slice expiration, and ensure that a DDoS attack sent that number of stray requests. An attack does not affect the stability of the kernel; it only causes mismanagement of application execution.) |
Ubuntu USN |
USN-4226-1 | Linux kernel vulnerabilities |
References
History
No history.
Subscriptions
Canonical
Subscribe
Ubuntu Linux
Subscribe
Debian
Subscribe
Debian Linux
Subscribe
Linux
Subscribe
Linux Kernel
Subscribe
Netapp
Subscribe
Active Iq Unified Manager
Subscribe
Aff Baseboard Management Controller
Subscribe
Cloud Backup
Subscribe
Data Availability Services
Subscribe
E-series Santricity Os Controller
Subscribe
Fas\/aff Baseboard Management Controller
Subscribe
Hci Baseboard Management Controller
Subscribe
Solidfire \& Hci Management Node
Subscribe
Solidfire Baseboard Management Controller
Subscribe
Steelstore Cloud Integrated Storage
Subscribe
Oracle
Subscribe
Sd-wan Edge
Subscribe
Redhat
Subscribe
Enterprise Linux
Subscribe
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T02:32:10.074Z
Reserved: 2019-12-22T00:00:00.000Z
Link: CVE-2019-19922
No data.
Status : Modified
Published: 2019-12-22T20:15:10.823
Modified: 2024-11-21T04:35:40.277
Link: CVE-2019-19922
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD
Ubuntu USN