PT-2019-4490 · Linux+4 · Linux Kernel+4
Published
2019-08-08
·
Updated
2022-12-14
·
CVE-2019-19922
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 5.3.9
Description
The issue is related to the cpu.cfs quota us function in the Linux kernel, which can lead to a denial of service against non-cpu-bound applications. This can be triggered by generating a workload that causes unwanted slice expiration. An attacker could potentially exploit this to force a Kubernetes cluster into a low-performance state by sending a calculated number of stray requests, effectively causing a DDoS attack. The attack does not affect kernel stability but rather mismanages application execution.
Recommendations
For Linux kernel versions prior to 5.3.9, update to version 5.3.9 or later to resolve the issue. As a temporary workaround, consider restricting the use of the cpu.cfs quota us function to minimize the risk of exploitation. Avoid using this function in conjunction with Kubernetes until the issue is resolved.
Exploit
Fix
DoS
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Centos
Linux Kernel
Red Hat
Ubuntu