FlawAtlas
Search the atlas
UBUNTU-CVE-2019-19922 Moderate

UBUNTU-CVE-2019-19922

kernel/sched/fair.c in the Linux kernel before 5.3.9, when cpu.cfs_quota_us is used (e.g., with Kubernetes), allows attackers to cause a denial of service against non-cpu-bound applications by generating a workload that triggers unwanted slice expiration, aka CID-de53fd7aedb1. (In other words, although this slice expiration would typically be seen with benign workloads, it is possible that an attacker could calculate how many stray requests are required to force an entire Kubernetes cluster into a low-performance state caused by slice expiration, and ensure that a DDoS attack sent that number of stray requests. An attack does not affect the stability of the kernel; it only causes mismanagement of application execution.)

Exploit probability Not scored
Published December 22, 2019
Required by Not available
Last source change April 22, 2026

02 / AFFECTED SOFTWARE

Affected packages

Ubuntu:16.04:LTS linux-oracle

16 explicit affected versions

Ubuntu:22.04:LTS linux-realtime

1 explicit affected versions

Ubuntu:18.04:LTS linux-gcp-edge

12 explicit affected versions

Ubuntu:18.04:LTS linux-oracle

16 explicit affected versions

Ubuntu:18.04:LTS linux-kvm

33 explicit affected versions

Ubuntu:18.04:LTS linux-gke-4.15

12 explicit affected versions

Ubuntu:16.04:LTS linux-aws-hwe

17 explicit affected versions

Ubuntu:16.04:LTS linux-azure

47 explicit affected versions

Ubuntu:22.04:LTS linux-riscv

23 explicit affected versions

Ubuntu:Pro:14.04:LTS linux-azure

24 explicit affected versions

Ubuntu:18.04:LTS linux-snapdragon

14 explicit affected versions

Ubuntu:16.04:LTS linux-gcp

40 explicit affected versions

Ubuntu:16.04:LTS linux-hwe

60 explicit affected versions

Ubuntu:20.04:LTS linux-gke

51 explicit affected versions

Ubuntu:18.04:LTS linux-raspi2

35 explicit affected versions

Ubuntu:18.04:LTS linux-aws

34 explicit affected versions

Ubuntu:18.04:LTS linux

39 explicit affected versions

Ubuntu:22.04:LTS linux-intel-iot-realtime

1 explicit affected versions

Ubuntu:18.04:LTS linux-hwe-edge

9 explicit affected versions

Ubuntu:24.04:LTS linux-raspi-realtime

1 explicit affected versions

Ubuntu:18.04:LTS linux-gcp-5.3

1 explicit affected versions

Ubuntu:20.04:LTS linux-raspi2

6 explicit affected versions

Ubuntu:18.04:LTS linux-gcp

33 explicit affected versions

Ubuntu:18.04:LTS linux-gke-5.0

9 explicit affected versions

Ubuntu:18.04:LTS linux-aws-5.0

2 explicit affected versions

Ubuntu:18.04:LTS linux-oem

27 explicit affected versions

Ubuntu:18.04:LTS linux-hwe

20 explicit affected versions

Ubuntu:16.04:LTS linux-hwe-edge

23 explicit affected versions

Ubuntu:20.04:LTS linux-azure-fde

26 explicit affected versions

Ubuntu:18.04:LTS linux-azure-edge

4 explicit affected versions

Ubuntu:18.04:LTS linux-oracle-5.0

2 explicit affected versions

Ubuntu:20.04:LTS linux-riscv

12 explicit affected versions

Ubuntu:18.04:LTS linux-azure-5.3

1 explicit affected versions

Ubuntu:18.04:LTS linux-azure

37 explicit affected versions

Ubuntu:18.04:LTS linux-oem-osp1

11 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities UBUNTU-CVE-2019-19922

kernel/sched/fair.c in the Linux kernel before 5.3.9, when cpu.cfs_quota_us is used (e.g., with Kubernetes), allows attackers to cause a denial of service against non-cpu-bound applications by generating a workload that triggers unwanted slice expiration, aka CID-de53fd7aedb1. (In other words, although this slice expiration would typically be seen with benign workloads, it is possible that an attacker could calculate how many stray requests are required to force an entire Kubernetes cluster into a low-performance state caused by slice expiration, and ensure that a DDoS attack sent that number of stray requests. An attack does not affect the stability of the kernel; it only causes mismanagement of application execution.)

View original source

05 / REFERENCES

Further evidence