kernel: SCTP socket buffer memory leak leading to denial of service
Published Mar 25, 2019
6.5
MEDIUMCVSS 3.1
EPSS 1.77%
Description
The SCTP socket buffer used by a userspace application is not accounted by the cgroups subsystem. An attacker can use this flaw to cause a denial of service attack. Kernel 3.10.x and 4.18.x branches are believed to be vulnerable.
Affected products
-
- Version 3.10.x and 4.18.xStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| The Linux Foundation | Kernel | n/a |
|
Configuration 1
- ≥ 3.10.1 · ≤ 3.10.108
- ≥ 4.18.1 · ≤ 4.18.20
Configuration 2
- 8.0
Configuration 3
- 7.0
Configuration 4
- 14.04
- 16.04
- 18.04
- 18.10
- 19.04
Configuration 5
- ≥ 9.5
- n/a
- n/a
- n/a
Configuration 6
- n/a
No data.
Red Hat Enterprise Linux 8
kernel-0:4.18.0-147.el8
Fixed · RHSA-2019:3517
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-147.rt24.93.el8
Fixed · RHSA-2019:3309
Red Hat Enterprise Linux 7
kernel
Will not fix
Red Hat Enterprise Linux 7
kernel-alt
Fix deferred
Red Hat Enterprise Linux 7
kernel-rt
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-147.el8 | Fixed | RHSA-2019:3517 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-147.rt24.93.el8 | Fixed | RHSA-2019:3309 |
| Red Hat Enterprise Linux 7 | kernel | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | kernel-alt | Fix deferred | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
While this issue affects the Linux Kernel in Red Hat Enterprise Linux, and not OpenShift Container Platform (OCP) 3 code directly. OCP 3 makes use of CGroups in the Kernel to measure and report on the amount of system resources used by an end user application. The default Security Context Constraints (SCC) in OpenShift Container Platform 3.x disallow an end user from running a container as root. Also a check is performed by the OCP 3 Installer to ensure SELinux is enabled, [1]. [1] https://github.com/openshift/openshift-ansible/blob/006fb14e9a28df9bd1a58ac376bbdf3eba50fa51/roles/openshift_node/tasks/main.yml#L3
Red Hat mitigation
SELinux prevents a bind of the SCTP socket by a non-root user. To mitigate this issue if not using SELinux, or if a Security Context Constraint allows running pods as the root user the 'sctp' module should be blacklisted. Please this this Knowledge Base article for more information on how to blacklist a kernel module. https://access.redhat.com/solutions/41278
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
AV:A/AC:L/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (15 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 1.77% (0.01771) | 77.33th | v5 (v2026.06.15) |
| Jun 15, 2026 | 1.77% (0.01771) | 75.17th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.06% (0.00056) | 14.82th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.37% (0.00369) | 73.42th | v3 (v2023.03.01) |
| Mar 18, 2024 | 0.37% (0.00369) | 71.98th | v3 (v2023.03.01) |
| Mar 3, 2024 | 0.32% (0.00315) | 69.64th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.22% (0.00222) | 58.65th | v3 (v2023.03.01) |
| Mar 6, 2023 | 2.69% (0.02686) | 82.85th | v2 (v2022.01.01) |
| Apr 1, 2022 | 2.69% (0.02686) | 81.17th | v2 (v2022.01.01) |
| Feb 4, 2022 | 7.83% (0.07834) | 81.57th | v2 (v2022.01.01) |
| Feb 3, 2022 | 14.23% (0.14227) | 89.43th | v1 |
| Jan 6, 2022 | 14.23% (0.14227) | 89.30th | v1 |
| Sep 1, 2021 | 3.56% (0.03565) | 82.04th | v1 |
| Jun 15, 2021 | 3.56% (0.03565) | 0.00th | v1 |
| Apr 14, 2021 | 3.32% (0.03317) | 0.00th | v1 |
References (19)
- https://access.redhat.com/errata/RHSA-2019:3309 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3517 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-3874 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1686373 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3874 x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory
- https://discuss.kubernetes.io/t/kubernetes-security-announcement-linux-kernel-memory-cgroups-escape-via-sctp-cve-2019-3874/5594
- https://lists.debian.org/debian-lts-announce/2020/09/msg00025.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lore.kernel.org/netdev/20190401113110.GA20717@hmswarspite.think-freely.org/T/#u
- https://nvd.nist.gov/vuln/detail/CVE-2019-3874
- https://security.netapp.com/advisory/ntap-20190411-0003/ x_refsource_CONFIRMThird Party Advisory
- https://usn.ubuntu.com/3979-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3980-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3980-2/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3981-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3981-2/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3982-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3982-2/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-3874
- https://www.oracle.com/security-alerts/cpuApr2021.html x_refsource_MISC
Change history (0)
No recorded changes yet.