cbcvebase.
CVE-2019-11478
published 2019-06-19

CVE-2019-11478: Jonathan Looney discovered that the TCP retransmission queue implementation in tcp_fragment in the Linux kernel could be fragmented when handling certain TCP…

PriorityP261high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
94.69%
99.8th percentile
Jonathan Looney discovered that the TCP retransmission queue implementation in tcp_fragment in the Linux kernel could be fragmented when handling certain TCP Selective Acknowledgment (SACK) sequences. A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11, and is fixed in commit f070ef2ac66716357066b683fb0baf55f8191a2e.

Affected

101 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debianlinux< linux 4.19.37-4 (bookworm)linux 4.19.37-4 (bookworm)
f5big-ip_access_policy_manager
f5big-ip_access_policy_manager11.5.2 – 11.6.4
f5big-ip_access_policy_manager12.1.0 – 12.1.4
f5big-ip_access_policy_manager13.1.0 – 13.1.1
f5big-ip_access_policy_manager14.0.0 – 14.1.0
f5big-ip_advanced_firewall_manager
f5big-ip_advanced_firewall_manager11.5.2 – 11.6.4
f5big-ip_advanced_firewall_manager12.1.0 – 12.1.4
f5big-ip_advanced_firewall_manager13.1.0 – 13.1.1
f5big-ip_advanced_firewall_manager14.0.0 – 14.1.0
f5big-ip_analytics
f5big-ip_analytics11.5.2 – 11.6.4
f5big-ip_analytics12.1.0 – 12.1.4
f5big-ip_analytics13.1.0 – 13.1.1
f5big-ip_analytics14.0.0 – 14.1.0
f5big-ip_application_acceleration_manager
f5big-ip_application_acceleration_manager11.5.2 – 11.6.4
f5big-ip_application_acceleration_manager12.1.0 – 12.1.4

Detection & IOCsextracted from sources · hover to see the quote

hashf070ef2ac66716357066b683fb0baf55f8191a2e
  • The patch PATCH_net_2_4.patch addresses CVE-2019-11478 (SACK slowness on kernels < 4.15 and excess resource usage on all Linux kernel versions); use this patch identifier to verify remediation status.
  • All Linux systems running kernel version 2.6.29 or above with open TCP service ports are vulnerable; prioritize detection on publicly exposed ports 80, 22, and 443.
  • ·Exploitation requires an established TCP connection; the attacker must be able to send TCP segments to an open TCP service port on the target. The attack is not exploitable against services that terminate TLS (e.g., classic/application ELBs with TLS termination) as those intermediaries absorb the malicious SACK sequence.
  • ·ElastiCache VPCs and Amazon EMR instances that have not been modified from defaults do not accept untrusted TCP connections and are not affected; only customer-modified configurations are at risk.

CVSS provenance

nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.