Attacker Value
Unknown
(0 users assessed)
Exploitability
Unknown
(0 users assessed)
User Interaction
None
Privileges Required
Low
Attack Vector
Local
0

CVE-2019-19922

Disclosure Date: December 22, 2019
Add MITRE ATT&CK tactics and techniques that apply to this CVE.

Description

kernel/sched/fair.c in the Linux kernel before 5.3.9, when cpu.cfs_quota_us is used (e.g., with Kubernetes), allows attackers to cause a denial of service against non-cpu-bound applications by generating a workload that triggers unwanted slice expiration, aka CID-de53fd7aedb1. (In other words, although this slice expiration would typically be seen with benign workloads, it is possible that an attacker could calculate how many stray requests are required to force an entire Kubernetes cluster into a low-performance state caused by slice expiration, and ensure that a DDoS attack sent that number of stray requests. An attack does not affect the stability of the kernel; it only causes mismanagement of application execution.)

Add Assessment

No one has assessed this topic. Be the first to add your voice to the community.

CVSS V3 Severity and Metrics
Base Score:
5.5 Medium
Impact Score:
3.6
Exploitability Score:
1.8
Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector (AV):
Local
Attack Complexity (AC):
Low
Privileges Required (PR):
Low
User Interaction (UI):
None
Scope (S):
Unchanged
Confidentiality (C):
None
Integrity (I):
None
Availability (A):
High

General Information

Vendors

  • canonical,
  • debian,
  • linux,
  • netapp,
  • oracle

Products

  • active iq unified manager -,
  • aff baseboard management controller a700,
  • cloud backup -,
  • data availability services -,
  • debian linux 8.0,
  • e-series santricity os controller,
  • fas/aff baseboard management controller -,
  • hci baseboard management controller h610s,
  • linux kernel,
  • sd-wan edge 8.2,
  • solidfire & hci management node -,
  • solidfire baseboard management controller -,
  • steelstore cloud integrated storage -,
  • ubuntu linux 18.04,
  • ubuntu linux 19.04
Technical Analysis