CVE-2019-11477
published 2019-06-19CVE-2019-11477: Jonathan Looney discovered that the TCP_SKB_CB(skb)->tcp_gso_segs value was subject to an integer overflow in the Linux kernel when handling TCP Selective…
PriorityP260high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
98.75%
99.9th percentile
Jonathan Looney discovered that the TCP_SKB_CB(skb)->tcp_gso_segs value was subject to an integer overflow in the Linux kernel when handling TCP Selective Acknowledgments (SACKs). A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11, and is fixed in commit 3b4929f65b0d8249f19a50245cd88ed1a2f78cff.
Affected
102 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | linux | < linux 4.19.37-4 (bookworm) | linux 4.19.37-4 (bookworm) |
| f5 | big-ip_access_policy_manager | — | — |
| f5 | big-ip_access_policy_manager | 11.5.2 – 11.6.4 | — |
| f5 | big-ip_access_policy_manager | 12.1.0 – 12.1.4 | — |
| f5 | big-ip_access_policy_manager | 13.1.0 – 13.1.1 | — |
| f5 | big-ip_access_policy_manager | 14.0.0 – 14.1.0 | — |
| f5 | big-ip_advanced_firewall_manager | — | — |
| f5 | big-ip_advanced_firewall_manager | 11.5.2 – 11.6.4 | — |
| f5 | big-ip_advanced_firewall_manager | 12.1.0 – 12.1.4 | — |
| f5 | big-ip_advanced_firewall_manager | 13.1.0 – 13.1.1 | — |
| f5 | big-ip_advanced_firewall_manager | 14.0.0 – 14.1.0 | — |
| f5 | big-ip_analytics | — | — |
| f5 | big-ip_analytics | 11.5.2 – 11.6.4 | — |
| f5 | big-ip_analytics | 12.1.0 – 12.1.4 | — |
| f5 | big-ip_analytics | 13.1.0 – 13.1.1 | — |
| f5 | big-ip_analytics | 14.0.0 – 14.1.0 | — |
| f5 | big-ip_application_acceleration_manager | — | — |
| f5 | big-ip_application_acceleration_manager | 11.5.2 – 11.6.4 | — |
| f5 | big-ip_application_acceleration_manager | 12.1.0 – 12.1.4 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Alert on unexpected kernel panic events on Linux hosts with open TCP service ports, particularly those running kernel versions 2.6.29 through 5.1.10. ↗
- ·The attack is only exploitable on Linux kernels >= 2.6.29 and < the patched stable releases (4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11); systems already on patched versions are not vulnerable. ↗
- ·Two separate patch files are required depending on kernel version: PATCH_net_1_4.patch for kernels >= 2.6.29, and additionally PATCH_net_1a.patch for kernels up to and including 4.14. ↗
- ·If patching is not immediately possible, firewall rules or traffic control policies blocking crafted SACK packets or enforcing a minimum MSS can mitigate the attack. ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
osv7.5HIGH
vendor_debian7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Hitachi Energy AFF66x
cisa_ics·2023-08-22·CVSS 7.4
[HIGH] Hitachi Energy AFF66x
ICS Advisory
##
Hitachi Energy AFF66x
Release DateAugust 22, 2023
Alert CodeICSA-23-234-01
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.6
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Hitachi Energy
- Equipment: AFF66x
- Vulnerabilities: Cross-site Scripting, Use of Insufficiently Random Values, Origin Validation Error, Integer Overflow or Wraparound, Uncontrolled Resource Consumption, NULL Pointer Dereference
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow an attacker to compromise availability, integrity, and confidentiality of the targeted devices.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
Hitachi Energy reports these vulnerabilities affect the following AFF660/665 products:
- AFF660/665
CISA ICS
Siemens Industrial Products (Update R)
cisa_ics·2022-05-12·CVSS 7.5
[HIGH] Siemens Industrial Products (Update R)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens Industrial Products (Update R)
Last RevisedMay 12, 2022
Alert CodeICSA-19-253-03
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.5
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: Industrial Products
- Vulnerabilities: Excessive Data Query Operations in a Large Data Table, Integer Overflow or Wraparound, Uncontrolled Resource Consumption
## 2. UPDATE INFORMATION
This updated advisory is a follow-up to the advisory update titled ICSA-19-253-04 Siemens Industrial Products (Update Q) published on April 14, 2022 to the ICS webpage on cisa.gov/
Oracle
Oracle Oracle Systems Risk Matrix: XCP Firmware (Linux Kernel) — CVE-2019-11477
vendor_oracle·2020-10-15·CVSS 7.5
CVE-2019-11477 [HIGH] Oracle Oracle Systems Risk Matrix: XCP Firmware (Linux Kernel) — CVE-2019-11477
Oracle Oracle Systems Risk Matrix: XCP Firmware (Linux Kernel) vulnerability
CVE: CVE-2019-11477
CVSS: 7.5
Protocol: TCP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2020 (OCT 2020)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Security (Kernel) — CVE-2019-11477
vendor_oracle·2020-01-15·CVSS 7.5
CVE-2019-11477 [HIGH] Oracle Oracle Communications Applications Risk Matrix: Security (Kernel) — CVE-2019-11477
Oracle Oracle Communications Applications Risk Matrix: Security (Kernel) vulnerability
CVE: CVE-2019-11477
CVSS: 7.5
Protocol: TCP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2020 (JAN 2020)
VMware
VMware product updates address Linux kernel vulnerabilities in TCP Selective Acknowledgement (SACK) (CVE-2019-11477, CVE-2019-11478)
vendor_vmware·2019-07-02·CVSS 7.5
CVE-2019-11477 [HIGH] VMware product updates address Linux kernel vulnerabilities in TCP Selective Acknowledgement (SACK) (CVE-2019-11477, CVE-2019-11478)
VMSA-2019-0010: VMware product updates address Linux kernel vulnerabilities in TCP Selective Acknowledgement (SACK) (CVE-2019-11477, CVE-2019-11478)
| Advisory Severity | Important | CVSSv3 Range | 5.3 - 7.5 | Synopsis | VMware product updates address Linux kernel vulnerabilities in TCP Selective Acknowledgement (SACK) (CVE-2019-11477, CVE-2019-11478) | Issue Date | 2019-07-02 | Updated On | 2020-02-25 | CVE(s) | CVE-2019-11477, and CVE-2019-11478 Container Service Extension
CVEs: CVE-2019-11477, CVE-2019-11478
Affected products: NSX-T, vCenter Server, vSphere
Palo Alto
PAN-SA-2019-0013 Information about TCP SACK Panic Findings in PAN-OS
vendor_paloalto·2019-06-27·CVSS 7.5
CVE-2019-11477 [HIGH] CWE-190 PAN-SA-2019-0013 Information about TCP SACK Panic Findings in PAN-OS
PAN-SA-2019-0013 Information about TCP SACK Panic Findings in PAN-OS
Palo Alto Networks is aware of recent vulnerability disclosures known as TCP SACK Panic vulnerabilities. (Ref: PAN-119745/ CVE-2019-11477, CVE-2019-11478, CVE-2019-11479) Successful
CVEs: CVE-2019-11477, CVE-2019-11478, CVE-2019-11479, CVE-2019-5599
Affected products: GlobalProtect, PAN-OS
Ivanti
Ivanti Security Advisory: CVE-2019-11477
vendor_ivanti·2019-06-19·CVSS 7.5
CVE-2019-11477 [HIGH] CWE-190 Ivanti Security Advisory: CVE-2019-11477
Ivanti Security Advisory: CVE-2019-11477
Jonathan Looney discovered that the TCP_SKB_CB(skb)->tcp_gso_segs value was subject to an integer overflow in the Linux kernel when handling TCP Selective Acknowledgments (SACKs). A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11, and is fixed in commit 3b4929f65b0d8249f19a50245cd88ed1a2f78cff.
CVE IDs: CVE-2019-11477
CVSS Base Score: 7.5
Severity: HIGH
CWEs: CWE-190
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2019-06-17·CVSS 7.5
CVE-2019-11477 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: The system could be made to crash if it received specially crafted
network traffic.
Jonathan Looney discovered that the TCP retransmission queue implementation
in the Linux kernel could be fragmented when handling certain TCP Selective
Acknowledgment (SACK) sequences. A remote attacker could use this to cause
a denial of service. (CVE-2019-11478)
Jonathan Looney discovered that an integer overflow existed in the Linux
kernel when handling TCP Selective Acknowledgments (SACKs). A remote
attacker could use this to cause a denial of service (system crash).
(CVE-2019-11477)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updat
Red Hat
Kernel: tcp: integer overflow while processing SACK blocks allows remote denial of service
vendor_redhat·2019-06-17·CVSS 7.5
CVE-2019-11477 [HIGH] CWE-190 Kernel: tcp: integer overflow while processing SACK blocks allows remote denial of service
Kernel: tcp: integer overflow while processing SACK blocks allows remote denial of service
Jonathan Looney discovered that the TCP_SKB_CB(skb)->tcp_gso_segs value was subject to an integer overflow in the Linux kernel when handling TCP Selective Acknowledgments (SACKs). A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11, and is fixed in commit 3b4929f65b0d8249f19a50245cd88ed1a2f78cff.
An integer overflow flaw was found in the way the Linux kernel's networking subsystem processed TCP Selective Acknowledgment (SACK) segments. While processing SACK segments, the Linux kernel's socket buffer (SKB) data structure becomes fragmented. Each fragment is about TCP maximum segment size (MSS) bytes.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2019-06-17·CVSS 7.5
CVE-2019-11477 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: The system could be made to crash if it received specially crafted
network traffic.
USN-4017-1 fixed vulnerabilities in the Linux kernel for Ubuntu.
This update provides the corresponding updates for the Linux kernel
for Ubuntu 16.04 ESM and Ubuntu 14.04 ESM.
Jonathan Looney discovered that the TCP retransmission queue implementation
in the Linux kernel could be fragmented when handling certain TCP Selective
Acknowledgment (SACK) sequences. A remote attacker could use this to cause
a denial of service. (CVE-2019-11478)
Jonathan Looney discovered that an integer overflow existed in the Linux
kernel when handling TCP Selective Acknowledgments (SACKs). A remote
attacker could use this to cause a denial of service (system crash).
(CVE-2019-11477
Debian
CVE-2019-11477: linux - Jonathan Looney discovered that the TCP_SKB_CB(skb)->tcp_gso_segs value was subj...
vendor_debian·2019·CVSS 7.5
CVE-2019-11477 [HIGH] CVE-2019-11477: linux - Jonathan Looney discovered that the TCP_SKB_CB(skb)->tcp_gso_segs value was subj...
Jonathan Looney discovered that the TCP_SKB_CB(skb)->tcp_gso_segs value was subject to an integer overflow in the Linux kernel when handling TCP Selective Acknowledgments (SACKs). A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11, and is fixed in commit 3b4929f65b0d8249f19a50245cd88ed1a2f78cff.
Scope: local
bookworm: resolved (fixed in 4.19.37-4)
bullseye: resolved (fixed in 4.19.37-4)
forky: resolved (fixed in 4.19.37-4)
sid: resolved (fixed in 4.19.37-4)
trixie: resolved (fixed in 4.19.37-4)
GHSA
GHSA-748j-px2m-cwgh: Jonathan Looney discovered that the TCP_SKB_CB(skb)->tcp_gso_segs value was subject to an integer overflow in the Linux kernel when handling TCP Selec
ghsa_unreviewed·2022-05-24
CVE-2019-11477 [HIGH] CWE-190 GHSA-748j-px2m-cwgh: Jonathan Looney discovered that the TCP_SKB_CB(skb)->tcp_gso_segs value was subject to an integer overflow in the Linux kernel when handling TCP Selec
Jonathan Looney discovered that the TCP_SKB_CB(skb)->tcp_gso_segs value was subject to an integer overflow in the Linux kernel when handling TCP Selective Acknowledgments (SACKs). A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11, and is fixed in commit 3b4929f65b0d8249f19a50245cd88ed1a2f78cff.
OSV
CVE-2019-11477: Jonathan Looney discovered that the TCP_SKB_CB(skb)->tcp_gso_segs value was subject to an integer overflow in the Linux kernel when handling TCP Selec
osv·2019-06-19·CVSS 7.5
CVE-2019-11477 [HIGH] CVE-2019-11477: Jonathan Looney discovered that the TCP_SKB_CB(skb)->tcp_gso_segs value was subject to an integer overflow in the Linux kernel when handling TCP Selec
Jonathan Looney discovered that the TCP_SKB_CB(skb)->tcp_gso_segs value was subject to an integer overflow in the Linux kernel when handling TCP Selective Acknowledgments (SACKs). A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11, and is fixed in commit 3b4929f65b0d8249f19a50245cd88ed1a2f78cff.
OSV
linux, linux-aws, linux-aws-hwe, linux-azure, linux-gcp, linux-hwe, linux-kvm, linux-oem, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities
osv·2019-06-17·CVSS 7.5
CVE-2019-11478 [HIGH] linux, linux-aws, linux-aws-hwe, linux-azure, linux-gcp, linux-hwe, linux-kvm, linux-oem, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities
linux, linux-aws, linux-aws-hwe, linux-azure, linux-gcp, linux-hwe, linux-kvm, linux-oem, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities
Jonathan Looney discovered that the TCP retransmission queue implementation
in the Linux kernel could be fragmented when handling certain TCP Selective
Acknowledgment (SACK) sequences. A remote attacker could use this to cause
a denial of service. (CVE-2019-11478)
Jonathan Looney discovered that an integer overflow existed in the Linux
kernel when handling TCP Selective Acknowledgments (SACKs). A remote
attacker could use this to cause a denial of service (system crash).
(CVE-2019-11477)
OSV
linux, linux-aws, linux-azure, linux-lts-trusty, linux-lts-xenial vulnerabilities
osv·2019-06-17·CVSS 7.5
[HIGH] linux, linux-aws, linux-azure, linux-lts-trusty, linux-lts-xenial vulnerabilities
linux, linux-aws, linux-azure, linux-lts-trusty, linux-lts-xenial vulnerabilities
USN-4017-1 fixed vulnerabilities in the Linux kernel for Ubuntu.
This update provides the corresponding updates for the Linux kernel
for Ubuntu 16.04 ESM and Ubuntu 14.04 ESM.
Jonathan Looney discovered that the TCP retransmission queue implementation
in the Linux kernel could be fragmented when handling certain TCP Selective
Acknowledgment (SACK) sequences. A remote attacker could use this to cause
a denial of service. (CVE-2019-11478)
Jonathan Looney discovered that an integer overflow existed in the Linux
kernel when handling TCP Selective Acknowledgments (SACKs). A remote
attacker could use this to cause a denial of service (system crash).
(CVE-2019-11477)
Kernel
tcp: limit payload size of sacked skbs
kernel_security·2019-05-17·CVSS 7.5
CVE-2019-11477 [HIGH] tcp: limit payload size of sacked skbs
tcp: limit payload size of sacked skbs
Jonathan Looney reported that TCP can trigger the following crash
in tcp_shifted_skb() :
BUG_ON(tcp_skb_pcount(skb) tcp_gso_segs
can overflow.
Note that tcp_sendmsg() builds skbs with less than 64KB
of payload, so this problem needs SACK to be enabled.
SACK blocks allow TCP to coalesce multiple skbs in the retransmit
queue, thus filling the 17 fragments to maximal capacity.
CVE-2019-11477 -- u16 overflow of TCP_SKB_CB(skb)->tcp_gso_segs
Fixes: 832d11c5cd07 ("tcp: Try to restore large SKBs while SACK processing")
Signed-off-by: Eric Dumazet
Reported-by: Jonathan Looney
Acked-by: Neal Cardwell
Reviewed-by: Tyler Hicks
Cc: Yuchung Cheng
Cc: Bruce Curtis
Cc: Jonathan Lemon
Signed-off-by: David S. Miller
No detection rules found.
No public exploits indexed.
Qualys
July 2019 Patch Tuesday – 77 Vulns, 15 Critical, DHCP RCE, Exploited PrivEsc, SQL, Adobe Vulns | Qualys
blogs_qualys·2019-07-09·CVSS 9.8
[CRITICAL] July 2019 Patch Tuesday – 77 Vulns, 15 Critical, DHCP RCE, Exploited PrivEsc, SQL, Adobe Vulns | Qualys
This month’s Microsoft Patch Tuesday addresses 77 vulnerabilities with 15 of them labeled as Critical. Of the 15 Critical vulns, 11 are for scripting engines and browsers, with the remaining four covering DHCP Server, GDI+, .NET Framework, and Azure DevOps Server / Team Foundation Server. In addition, Microsoft has released Important patches for two actively exploited privilege escalation vulnerabilities, as well as a SQL Server RCE. Microsoft also issued two advisories for Outlook on the web and Linux Kernel vulnerabilities. Adobe issued patches today for Bridge CC, Experience Manager, and Dreamweaver.
### Workstation Patches
Scripting Engine, Browser, GDI+, and .NET Framework patches should be prioritized for workstation-type devices, meaning any system that is used for email or to acc
Qualys
July 2019 Patch Tuesday – 77 Vulns, 15 Critical, DHCP RCE, Exploited PrivEsc, SQL, Adobe Vulns
blogs_qualys·2019-07-09·CVSS 9.8
[CRITICAL] July 2019 Patch Tuesday – 77 Vulns, 15 Critical, DHCP RCE, Exploited PrivEsc, SQL, Adobe Vulns
This month’s Microsoft Patch Tuesday addresses 77 vulnerabilities with 15 of them labeled as Critical. Of the 15 Critical vulns, 11 are for scripting engines and browsers, with the remaining four covering DHCP Server, GDI+, .NET Framework, and Azure DevOps Server / Team Foundation Server. In addition, Microsoft has released Important patches for two actively exploited privilege escalation vulnerabilities, as well as a SQL Server RCE. Microsoft also issued two advisories for Outlook on the web and Linux Kernel vulnerabilities. Adobe issued patches today for Bridge CC, Experience Manager, and Dreamweaver.
## Workstation Patches
Scripting Engine, Browser, GDI+, and .NET Framework patches should be prioritized for workstation-type devices, meaning any system that is used for email or to acce
Checkpoint
24th June – Threat Intelligence Bulletin
blogs_checkpoint·2019-06-24
CVE-2019-7406 24th June – Threat Intelligence Bulletin
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 24th June – Threat Intelligence Bulletin
For the latest discoveries in cyber research for the week of 24th June 2019, please download our Threat Intelligence Bulletin
TOP ATTACKS AND BREACHES
Oregon’s Department of Human Services has announced that it was a victim of a data breach, potentially impacting the personal details and health information of 645,000 clients. The breach happened last January, following a phishing attack that hit the department where at least 9 employees were deceived.
Canadian Desjardin
Unit42
TCP SACK Panics Linux Servers
blogs_unit42·2019-06-21·CVSS 7.5
CVE-2019-11477 [HIGH] TCP SACK Panics Linux Servers
#### Executive Summary
The newly discovered Linux vulnerabilities, CVE-2019-11477, CVE-2019-11478, and CVE-2019-11479, affect all Linux operating systems newer than kernel 2.6.29 (released on March 2009) or above and can cause a kernel panic to systems with services listening on a TCP connection. This remote attack can put a server into a Denial of Service (DoS) state, but remote code execution is not of concern. The vulnerability roots on the flaws in the TCP Selective Acknowledgement (SACK) and Maximum Segment Size (MSS) implementation. The attack can be triggered by a remote user who sets the MSS to the lowest limit of 48 bytes and sends a sequence of specially crafted SACK packets to overflow the receiver’s socket buffer. Most of the Linux distributions have released a patch, RedHat,
Unit42
TCP SACK Panics Linux Servers
blogs_unit42·2019-06-21·CVSS 7.5
CVE-2019-11477 [HIGH] TCP SACK Panics Linux Servers
Threat Research Center
Threat Research
Cloud Cybersecurity Research
## TCP SACK Panics Linux Servers
Unit 42
Published: June 21, 2019
Cloud Cybersecurity Research
Threat Research
Vulnerabilities
AWS
Azure
CVE-2019-11477
CVE-2019-11478
CVE-2019-11479
GCP
Linux
Public cloud
SACK
## Executive Summary
The newly discovered Linux vulnerabilities , CVE-2019-11477 , CVE-2019-11478 , and CVE-2019-11479 , affect all Linux operating systems newer than kernel 2.6.29 (released on March 2009) or above and can cause a kernel panic to systems with services listening on a TCP connection. This remote attack can put a server into a Denial of Service (DoS) state, but remote code execution is not of concern. The vulnerability roots on the flaws in the TCP Selective Acknowledgement (SACK)
Tenable
SACK Panic: Linux and FreeBSD Kernels Vulnerable to Remote Denial of Service Vulnerabilities (CVE-2019-11477)
blogs_tenable·2019-06-18·CVSS 7.5
[HIGH] SACK Panic: Linux and FreeBSD Kernels Vulnerable to Remote Denial of Service Vulnerabilities (CVE-2019-11477)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bugzilla
CVE-2019-11477 kernel: tcp: integer overflow while processing SACK blocks allows remote denial of service [fedora-all]
bugzilla·2019-06-17·CVSS 7.5
CVE-2019-11477 [HIGH] CVE-2019-11477 kernel: tcp: integer overflow while processing SACK blocks allows remote denial of service [fedora-all]
CVE-2019-11477 kernel: tcp: integer overflow while processing SACK blocks allows remote denial of service [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this
Bugzilla
CVE-2019-11477 Kernel: tcp: integer overflow while processing SACK blocks allows remote denial of service
bugzilla·2019-06-11·CVSS 7.5
CVE-2019-11477 [HIGH] CVE-2019-11477 Kernel: tcp: integer overflow while processing SACK blocks allows remote denial of service
CVE-2019-11477 Kernel: tcp: integer overflow while processing SACK blocks allows remote denial of service
An integer overflow issue was found in the way Linux kernel processes TCP
Selective Acknowledgement(SACK) segments. While processing SACK segments, Linux
kernel's socket buffer(SBK) data structure becomes fragmented. Each fragment is
about TCP MSS bytes. To efficiently process SACK blocks, Linux combines multiple
fragmented SKB into one. This merging of SKB results in the said integer overflow
issue, as more number of segments exceed the 16bit width of
'TCP_SKB_CB(skb)->tcp_gso_segs' parameter in tcp_shifted_skb() routine.
A remote attacker could use this flaw to crash the Linux kernel by sending a
crafted sequence of SACK segments on a TCP connection with minimum value of TCP
MSS, r
http://packetstormsecurity.com/files/153346/Kernel-Live-Patch-Security-Notice-LSN-0052-1.htmlhttp://packetstormsecurity.com/files/154951/Kernel-Live-Patch-Security-Notice-LSN-0058-1.htmlhttp://www.arubanetworks.com/assets/alert/ARUBA-PSA-2020-010.txthttp://www.huawei.com/en/psirt/security-advisories/huawei-sa-20191225-01-kernel-enhttp://www.openwall.com/lists/oss-security/2019/06/20/3http://www.openwall.com/lists/oss-security/2019/06/28/2http://www.openwall.com/lists/oss-security/2019/07/06/3http://www.openwall.com/lists/oss-security/2019/07/06/4http://www.openwall.com/lists/oss-security/2019/10/24/1http://www.openwall.com/lists/oss-security/2019/10/29/3http://www.vmware.com/security/advisories/VMSA-2019-0010.htmlhttps://access.redhat.com/errata/RHSA-2019:1594https://access.redhat.com/errata/RHSA-2019:1602https://access.redhat.com/errata/RHSA-2019:1699https://access.redhat.com/security/vulnerabilities/tcpsackhttps://cert-portal.siemens.com/productcert/pdf/ssa-462066.pdfhttps://git.kernel.org/pub/scm/linux/kernel/git/davem/net.git/commit/?id=3b4929f65b0d8249f19a50245cd88ed1a2f78cffhttps://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-001.mdhttps://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44193https://kc.mcafee.com/corporate/index?page=content&id=SB10287https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2019-0006https://security.netapp.com/advisory/ntap-20190625-0001/https://support.f5.com/csp/article/K78234183https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/SACKPanichttps://www.kb.cert.org/vuls/id/905115https://www.oracle.com/security-alerts/cpujan2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttps://www.synology.com/security/advisory/Synology_SA_19_28https://www.us-cert.gov/ics/advisories/icsa-19-253-03http://packetstormsecurity.com/files/153346/Kernel-Live-Patch-Security-Notice-LSN-0052-1.htmlhttp://packetstormsecurity.com/files/154951/Kernel-Live-Patch-Security-Notice-LSN-0058-1.htmlhttp://www.arubanetworks.com/assets/alert/ARUBA-PSA-2020-010.txthttp://www.huawei.com/en/psirt/security-advisories/huawei-sa-20191225-01-kernel-enhttp://www.openwall.com/lists/oss-security/2019/06/20/3http://www.openwall.com/lists/oss-security/2019/06/28/2http://www.openwall.com/lists/oss-security/2019/07/06/3http://www.openwall.com/lists/oss-security/2019/07/06/4http://www.openwall.com/lists/oss-security/2019/10/24/1http://www.openwall.com/lists/oss-security/2019/10/29/3http://www.vmware.com/security/advisories/VMSA-2019-0010.htmlhttps://access.redhat.com/errata/RHSA-2019:1594https://access.redhat.com/errata/RHSA-2019:1602https://access.redhat.com/errata/RHSA-2019:1699https://access.redhat.com/security/vulnerabilities/tcpsackhttps://cert-portal.siemens.com/productcert/pdf/ssa-462066.pdfhttps://git.kernel.org/pub/scm/linux/kernel/git/davem/net.git/commit/?id=3b4929f65b0d8249f19a50245cd88ed1a2f78cffhttps://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-001.mdhttps://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44193https://kc.mcafee.com/corporate/index?page=content&id=SB10287https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2019-0006https://security.netapp.com/advisory/ntap-20190625-0001/https://support.f5.com/csp/article/K78234183https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/SACKPanichttps://www.kb.cert.org/vuls/id/905115https://www.oracle.com/security-alerts/cpujan2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttps://www.synology.com/security/advisory/Synology_SA_19_28https://www.us-cert.gov/ics/advisories/icsa-19-253-03
2019-06-19
Published