kernel: when cpu.cfs_quota_us is used allows attackers to cause a denial of service against non-cpu-bound applications
Published Dec 22, 2019
5.5
MEDIUMCVSS 3.1
EPSS 0.95%
Description
kernel/sched/fair.c in the Linux kernel before 5.3.9, when cpu.cfs_quota_us is used (e.g., with Kubernetes), allows attackers to cause a denial of service against non-cpu-bound applications by generating a workload that triggers unwanted slice expiration, aka CID-de53fd7aedb1. (In other words, although this slice expiration would typically be seen with benign workloads, it is possible that an attacker could calculate how many stray requests are required to force an entire Kubernetes cluster into a low-performance state caused by slice expiration, and ensure that a DDoS attack sent that number of stray requests. An attack does not affect the stability of the kernel; it only causes mismanagement of application execution.)
Affected products
No data.
Configuration 1
- < 5.3.9
Configuration 2
- 8.2
- 18.04
- 19.04
- 8.0
Configuration 3
- n/a
- n/a
- n/a
- ≥ 11.0 · ≤ 11.70.2
- n/a
- h610s
- n/a
- n/a
- a700
- n/a
No data.
Red Hat Enterprise Linux 7
kernel-alt-0:4.14.0-115.19.1.el7a
Fixed · RHSA-2020:1493
Red Hat Enterprise Linux 8
kernel-0:4.18.0-193.el8
Fixed · RHSA-2020:1769
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-193.rt13.51.el8
Fixed · RHSA-2020:1567
Red Hat Enterprise Linux 5
kernel
Out of support scope
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise MRG 2
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | kernel-alt-0:4.14.0-115.19.1.el7a | Fixed | RHSA-2020:1493 |
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-193.el8 | Fixed | RHSA-2020:1769 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-193.rt13.51.el8 | Fixed | RHSA-2020:1567 |
| Red Hat Enterprise Linux 5 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise MRG 2 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (14)
- https://access.redhat.com/security/cve/CVE-2019-19922 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1792512 Issue Tracking
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.3.9 x_refsource_MISCMailing ListPatchVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-9511 Advisory
- https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=de53fd7aedb100f03e5d2231cfce0e4993282425 x_refsource_MISCMailing ListPatchVendor Advisory
- https://github.com/kubernetes/kubernetes/issues/67577 x_refsource_MISCIssue TrackingPatchThird Party Advisory
- https://github.com/torvalds/linux/commit/de53fd7aedb100f03e5d2231cfce0e4993282425 x_refsource_MISCPatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/01/msg00013.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-19922
- https://relistan.com/the-kernel-may-be-slowing-down-your-app x_refsource_MISCExploitThird Party Advisory
- https://security.netapp.com/advisory/ntap-20200204-0002/ x_refsource_CONFIRMThird Party Advisory
- https://usn.ubuntu.com/4226-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-19922
- https://www.oracle.com/security-alerts/cpuApr2021.html x_refsource_MISCPatchThird Party Advisory
Change history (0)
No recorded changes yet.