PT-2019-4490 · Linux+4 · Linux Kernel+4
Publicado
2019-08-08
·
Atualizado
2022-12-14
·
CVE-2019-19922
CVSS v3.1
5.5
Média
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 5.3.9
Description
The issue is related to the cpu.cfs quota us function in the Linux kernel, which can lead to a denial of service against non-cpu-bound applications. This can be triggered by generating a workload that causes unwanted slice expiration. An attacker could potentially exploit this to force a Kubernetes cluster into a low-performance state by sending a calculated number of stray requests, effectively causing a DDoS attack. The attack does not affect kernel stability but rather mismanages application execution.
Recommendations
For Linux kernel versions prior to 5.3.9, update to version 5.3.9 or later to resolve the issue. As a temporary workaround, consider restricting the use of the cpu.cfs quota us function to minimize the risk of exploitation. Avoid using this function in conjunction with Kubernetes until the issue is resolved.
Exploit
Correção
DoS
Resource Exhaustion
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Centos
Linux Kernel
Red Hat
Ubuntu