CVE-2019-11478
published 2019-06-19CVE-2019-11478: Jonathan Looney discovered that the TCP retransmission queue implementation in tcp_fragment in the Linux kernel could be fragmented when handling certain TCP…
PriorityP261high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
94.69%
99.8th percentile
Jonathan Looney discovered that the TCP retransmission queue implementation in tcp_fragment in the Linux kernel could be fragmented when handling certain TCP Selective Acknowledgment (SACK) sequences. A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11, and is fixed in commit f070ef2ac66716357066b683fb0baf55f8191a2e.
Affected
101 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | linux | < linux 4.19.37-4 (bookworm) | linux 4.19.37-4 (bookworm) |
| f5 | big-ip_access_policy_manager | — | — |
| f5 | big-ip_access_policy_manager | 11.5.2 – 11.6.4 | — |
| f5 | big-ip_access_policy_manager | 12.1.0 – 12.1.4 | — |
| f5 | big-ip_access_policy_manager | 13.1.0 – 13.1.1 | — |
| f5 | big-ip_access_policy_manager | 14.0.0 – 14.1.0 | — |
| f5 | big-ip_advanced_firewall_manager | — | — |
| f5 | big-ip_advanced_firewall_manager | 11.5.2 – 11.6.4 | — |
| f5 | big-ip_advanced_firewall_manager | 12.1.0 – 12.1.4 | — |
| f5 | big-ip_advanced_firewall_manager | 13.1.0 – 13.1.1 | — |
| f5 | big-ip_advanced_firewall_manager | 14.0.0 – 14.1.0 | — |
| f5 | big-ip_analytics | — | — |
| f5 | big-ip_analytics | 11.5.2 – 11.6.4 | — |
| f5 | big-ip_analytics | 12.1.0 – 12.1.4 | — |
| f5 | big-ip_analytics | 13.1.0 – 13.1.1 | — |
| f5 | big-ip_analytics | 14.0.0 – 14.1.0 | — |
| f5 | big-ip_application_acceleration_manager | — | — |
| f5 | big-ip_application_acceleration_manager | 11.5.2 – 11.6.4 | — |
| f5 | big-ip_application_acceleration_manager | 12.1.0 – 12.1.4 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →The patch PATCH_net_2_4.patch addresses CVE-2019-11478 (SACK slowness on kernels < 4.15 and excess resource usage on all Linux kernel versions); use this patch identifier to verify remediation status. ↗
- →All Linux systems running kernel version 2.6.29 or above with open TCP service ports are vulnerable; prioritize detection on publicly exposed ports 80, 22, and 443. ↗
- ·Exploitation requires an established TCP connection; the attacker must be able to send TCP segments to an open TCP service port on the target. The attack is not exploitable against services that terminate TLS (e.g., classic/application ELBs with TLS termination) as those intermediaries absorb the malicious SACK sequence. ↗
- ·ElastiCache VPCs and Amazon EMR instances that have not been modified from defaults do not accept untrusted TCP connections and are not affected; only customer-modified configurations are at risk. ↗
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens Industrial Products (Update R)
cisa_ics·2022-05-12·CVSS 7.5
[HIGH] Siemens Industrial Products (Update R)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens Industrial Products (Update R)
Last RevisedMay 12, 2022
Alert CodeICSA-19-253-03
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.5
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: Industrial Products
- Vulnerabilities: Excessive Data Query Operations in a Large Data Table, Integer Overflow or Wraparound, Uncontrolled Resource Consumption
## 2. UPDATE INFORMATION
This updated advisory is a follow-up to the advisory update titled ICSA-19-253-04 Siemens Industrial Products (Update Q) published on April 14, 2022 to the ICS webpage on cisa.gov/
VMware
VMware product updates address Linux kernel vulnerabilities in TCP Selective Acknowledgement (SACK) (CVE-2019-11477, CVE-2019-11478)
vendor_vmware·2019-07-02·CVSS 7.5
CVE-2019-11477 [HIGH] VMware product updates address Linux kernel vulnerabilities in TCP Selective Acknowledgement (SACK) (CVE-2019-11477, CVE-2019-11478)
VMSA-2019-0010: VMware product updates address Linux kernel vulnerabilities in TCP Selective Acknowledgement (SACK) (CVE-2019-11477, CVE-2019-11478)
| Advisory Severity | Important | CVSSv3 Range | 5.3 - 7.5 | Synopsis | VMware product updates address Linux kernel vulnerabilities in TCP Selective Acknowledgement (SACK) (CVE-2019-11477, CVE-2019-11478) | Issue Date | 2019-07-02 | Updated On | 2020-02-25 | CVE(s) | CVE-2019-11477, and CVE-2019-11478 Container Service Extension
CVEs: CVE-2019-11477, CVE-2019-11478
Affected products: NSX-T, vCenter Server, vSphere
Palo Alto
PAN-SA-2019-0013 Information about TCP SACK Panic Findings in PAN-OS
vendor_paloalto·2019-06-27·CVSS 7.5
CVE-2019-11477 [HIGH] CWE-190 PAN-SA-2019-0013 Information about TCP SACK Panic Findings in PAN-OS
PAN-SA-2019-0013 Information about TCP SACK Panic Findings in PAN-OS
Palo Alto Networks is aware of recent vulnerability disclosures known as TCP SACK Panic vulnerabilities. (Ref: PAN-119745/ CVE-2019-11477, CVE-2019-11478, CVE-2019-11479) Successful
CVEs: CVE-2019-11477, CVE-2019-11478, CVE-2019-11479, CVE-2019-5599
Affected products: GlobalProtect, PAN-OS
Ivanti
Ivanti Security Advisory: CVE-2019-11478
vendor_ivanti·2019-06-19·CVSS 5.3
CVE-2019-11478 [MEDIUM] CWE-400 Ivanti Security Advisory: CVE-2019-11478
Ivanti Security Advisory: CVE-2019-11478
Jonathan Looney discovered that the TCP retransmission queue implementation in tcp_fragment in the Linux kernel could be fragmented when handling certain TCP Selective Acknowledgment (SACK) sequences. A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11, and is fixed in commit f070ef2ac66716357066b683fb0baf55f8191a2e.
CVE IDs: CVE-2019-11478
CVSS Base Score: 5.3
Severity: MEDIUM
CWEs: CWE-400, CWE-770
Red Hat
Kernel: tcp: excessive resource consumption while processing SACK blocks allows remote denial of service
vendor_redhat·2019-06-17·CVSS 5.3
CVE-2019-11478 [MEDIUM] CWE-400 Kernel: tcp: excessive resource consumption while processing SACK blocks allows remote denial of service
Kernel: tcp: excessive resource consumption while processing SACK blocks allows remote denial of service
Jonathan Looney discovered that the TCP retransmission queue implementation in tcp_fragment in the Linux kernel could be fragmented when handling certain TCP Selective Acknowledgment (SACK) sequences. A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11, and is fixed in commit f070ef2ac66716357066b683fb0baf55f8191a2e.
An excessive resource consumption flaw was found in the way the Linux kernel's networking subsystem processed TCP Selective Acknowledgment (SACK) segments. While processing SACK segments, the Linux kernel's socket buffer (SKB) data structure becomes fragmented, which leads
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2019-06-17·CVSS 7.5
CVE-2019-11477 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: The system could be made to crash if it received specially crafted
network traffic.
Jonathan Looney discovered that the TCP retransmission queue implementation
in the Linux kernel could be fragmented when handling certain TCP Selective
Acknowledgment (SACK) sequences. A remote attacker could use this to cause
a denial of service. (CVE-2019-11478)
Jonathan Looney discovered that an integer overflow existed in the Linux
kernel when handling TCP Selective Acknowledgments (SACKs). A remote
attacker could use this to cause a denial of service (system crash).
(CVE-2019-11477)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updat
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2019-06-17·CVSS 7.5
CVE-2019-11477 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: The system could be made to crash if it received specially crafted
network traffic.
USN-4017-1 fixed vulnerabilities in the Linux kernel for Ubuntu.
This update provides the corresponding updates for the Linux kernel
for Ubuntu 16.04 ESM and Ubuntu 14.04 ESM.
Jonathan Looney discovered that the TCP retransmission queue implementation
in the Linux kernel could be fragmented when handling certain TCP Selective
Acknowledgment (SACK) sequences. A remote attacker could use this to cause
a denial of service. (CVE-2019-11478)
Jonathan Looney discovered that an integer overflow existed in the Linux
kernel when handling TCP Selective Acknowledgments (SACKs). A remote
attacker could use this to cause a denial of service (system crash).
(CVE-2019-11477
Debian
CVE-2019-11478: linux - Jonathan Looney discovered that the TCP retransmission queue implementation in t...
vendor_debian·2019·CVSS 5.3
CVE-2019-11478 [MEDIUM] CVE-2019-11478: linux - Jonathan Looney discovered that the TCP retransmission queue implementation in t...
Jonathan Looney discovered that the TCP retransmission queue implementation in tcp_fragment in the Linux kernel could be fragmented when handling certain TCP Selective Acknowledgment (SACK) sequences. A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11, and is fixed in commit f070ef2ac66716357066b683fb0baf55f8191a2e.
Scope: local
bookworm: resolved (fixed in 4.19.37-4)
bullseye: resolved (fixed in 4.19.37-4)
forky: resolved (fixed in 4.19.37-4)
sid: resolved (fixed in 4.19.37-4)
trixie: resolved (fixed in 4.19.37-4)
GHSA
GHSA-xh2h-cw6h-x9h5: Jonathan Looney discovered that the TCP retransmission queue implementation in tcp_fragment in the Linux kernel could be fragmented when handling cert
ghsa_unreviewed·2022-05-24
CVE-2019-11478 [HIGH] CWE-400 GHSA-xh2h-cw6h-x9h5: Jonathan Looney discovered that the TCP retransmission queue implementation in tcp_fragment in the Linux kernel could be fragmented when handling cert
Jonathan Looney discovered that the TCP retransmission queue implementation in tcp_fragment in the Linux kernel could be fragmented when handling certain TCP Selective Acknowledgment (SACK) sequences. A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11, and is fixed in commit f070ef2ac66716357066b683fb0baf55f8191a2e.
Kernel
tcp: be more careful in tcp_fragment()
kernel_security·2019-07-19·CVSS 5.3
CVE-2019-11478 [MEDIUM] tcp: be more careful in tcp_fragment()
tcp: be more careful in tcp_fragment()
Some applications set tiny SO_SNDBUF values and expect
TCP to just work. Recent patches to address CVE-2019-11478
broke them in case of losses, since retransmits might
be prevented.
We should allow these flows to make progress.
This patch allows the first and last skb in retransmit queue
to be split even if memory limits are hit.
It also adds the some room due to the fact that tcp_sendmsg()
and tcp_sendpage() might overshoot sk_wmem_queued by about one full
TSO skb (64KB size). Note this allowance was already present
in stable backports for kernels
Reported-by: Andrew Prout
Tested-by: Andrew Prout
Tested-by: Jonathan Lemon
Tested-by: Michal Kubecek
Acked-by: Neal Cardwell
Acked-by: Yuchung Cheng
Acked-by: Christoph Paasch
Cc: Jonathan Looney
Signe
OSV
CVE-2019-11478: Jonathan Looney discovered that the TCP retransmission queue implementation in tcp_fragment in the Linux kernel could be fragmented when handling cert
osv·2019-06-19·CVSS 7.5
CVE-2019-11478 [HIGH] CVE-2019-11478: Jonathan Looney discovered that the TCP retransmission queue implementation in tcp_fragment in the Linux kernel could be fragmented when handling cert
Jonathan Looney discovered that the TCP retransmission queue implementation in tcp_fragment in the Linux kernel could be fragmented when handling certain TCP Selective Acknowledgment (SACK) sequences. A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11, and is fixed in commit f070ef2ac66716357066b683fb0baf55f8191a2e.
OSV
linux, linux-aws, linux-aws-hwe, linux-azure, linux-gcp, linux-hwe, linux-kvm, linux-oem, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities
osv·2019-06-17·CVSS 7.5
CVE-2019-11478 [HIGH] linux, linux-aws, linux-aws-hwe, linux-azure, linux-gcp, linux-hwe, linux-kvm, linux-oem, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities
linux, linux-aws, linux-aws-hwe, linux-azure, linux-gcp, linux-hwe, linux-kvm, linux-oem, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities
Jonathan Looney discovered that the TCP retransmission queue implementation
in the Linux kernel could be fragmented when handling certain TCP Selective
Acknowledgment (SACK) sequences. A remote attacker could use this to cause
a denial of service. (CVE-2019-11478)
Jonathan Looney discovered that an integer overflow existed in the Linux
kernel when handling TCP Selective Acknowledgments (SACKs). A remote
attacker could use this to cause a denial of service (system crash).
(CVE-2019-11477)
OSV
linux, linux-aws, linux-azure, linux-lts-trusty, linux-lts-xenial vulnerabilities
osv·2019-06-17·CVSS 7.5
[HIGH] linux, linux-aws, linux-azure, linux-lts-trusty, linux-lts-xenial vulnerabilities
linux, linux-aws, linux-azure, linux-lts-trusty, linux-lts-xenial vulnerabilities
USN-4017-1 fixed vulnerabilities in the Linux kernel for Ubuntu.
This update provides the corresponding updates for the Linux kernel
for Ubuntu 16.04 ESM and Ubuntu 14.04 ESM.
Jonathan Looney discovered that the TCP retransmission queue implementation
in the Linux kernel could be fragmented when handling certain TCP Selective
Acknowledgment (SACK) sequences. A remote attacker could use this to cause
a denial of service. (CVE-2019-11478)
Jonathan Looney discovered that an integer overflow existed in the Linux
kernel when handling TCP Selective Acknowledgments (SACKs). A remote
attacker could use this to cause a denial of service (system crash).
(CVE-2019-11477)
Kernel
tcp: tcp_fragment() should apply sane memory limits
kernel_security·2019-05-18·CVSS 5.3
CVE-2019-11478 [MEDIUM] tcp: tcp_fragment() should apply sane memory limits
tcp: tcp_fragment() should apply sane memory limits
Jonathan Looney reported that a malicious peer can force a sender
to fragment its retransmit queue into tiny skbs, inflating memory
usage and/or overflow 32bit counters.
TCP allows an application to queue up to sk_sndbuf bytes,
so we need to give some allowance for non malicious splitting
of retransmit queue.
A new SNMP counter is added to monitor how many times TCP
did not allow to split an skb if the allowance was exceeded.
Note that this counter might increase in the case applications
use SO_SNDBUF socket option to lower sk_sndbuf.
CVE-2019-11478 : tcp_fragment, prevent fragmenting a packet when the
socket is already using more than half the allowed space
Signed-off-by: Eric Dumazet
Reported-by: Jonathan Looney
Acked-by: Neal Car
No detection rules found.
No public exploits indexed.
Checkpoint
28th October – Threat Intelligence Bulletin
blogs_checkpoint·2019-10-28
CVE-2019-11478 28th October – Threat Intelligence Bulletin
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 28th October – Threat Intelligence Bulletin
For the latest discoveries in cyber research for the week of 28th October 2019, please download our Threat Intelligence Bulletin .
TOP ATTACKS AND BREACHES
Procter & Gamble’s site, ‘First Aid Beauty’ has been infected by a Magecart credit card skimmer for the past five months. The heavily obfuscated and encrypted skimmer specifically targeted US victims using Windows systems. Earlier this week the FBI has issued a warning advising SMSB to beware of E-skimming attacks.
Qualys
July 2019 Patch Tuesday – 77 Vulns, 15 Critical, DHCP RCE, Exploited PrivEsc, SQL, Adobe Vulns | Qualys
blogs_qualys·2019-07-09·CVSS 9.8
[CRITICAL] July 2019 Patch Tuesday – 77 Vulns, 15 Critical, DHCP RCE, Exploited PrivEsc, SQL, Adobe Vulns | Qualys
This month’s Microsoft Patch Tuesday addresses 77 vulnerabilities with 15 of them labeled as Critical. Of the 15 Critical vulns, 11 are for scripting engines and browsers, with the remaining four covering DHCP Server, GDI+, .NET Framework, and Azure DevOps Server / Team Foundation Server. In addition, Microsoft has released Important patches for two actively exploited privilege escalation vulnerabilities, as well as a SQL Server RCE. Microsoft also issued two advisories for Outlook on the web and Linux Kernel vulnerabilities. Adobe issued patches today for Bridge CC, Experience Manager, and Dreamweaver.
### Workstation Patches
Scripting Engine, Browser, GDI+, and .NET Framework patches should be prioritized for workstation-type devices, meaning any system that is used for email or to acc
Qualys
July 2019 Patch Tuesday – 77 Vulns, 15 Critical, DHCP RCE, Exploited PrivEsc, SQL, Adobe Vulns
blogs_qualys·2019-07-09·CVSS 9.8
[CRITICAL] July 2019 Patch Tuesday – 77 Vulns, 15 Critical, DHCP RCE, Exploited PrivEsc, SQL, Adobe Vulns
This month’s Microsoft Patch Tuesday addresses 77 vulnerabilities with 15 of them labeled as Critical. Of the 15 Critical vulns, 11 are for scripting engines and browsers, with the remaining four covering DHCP Server, GDI+, .NET Framework, and Azure DevOps Server / Team Foundation Server. In addition, Microsoft has released Important patches for two actively exploited privilege escalation vulnerabilities, as well as a SQL Server RCE. Microsoft also issued two advisories for Outlook on the web and Linux Kernel vulnerabilities. Adobe issued patches today for Bridge CC, Experience Manager, and Dreamweaver.
## Workstation Patches
Scripting Engine, Browser, GDI+, and .NET Framework patches should be prioritized for workstation-type devices, meaning any system that is used for email or to acce
Unit42
TCP SACK Panics Linux Servers
blogs_unit42·2019-06-21·CVSS 7.5
CVE-2019-11477 [HIGH] TCP SACK Panics Linux Servers
#### Executive Summary
The newly discovered Linux vulnerabilities, CVE-2019-11477, CVE-2019-11478, and CVE-2019-11479, affect all Linux operating systems newer than kernel 2.6.29 (released on March 2009) or above and can cause a kernel panic to systems with services listening on a TCP connection. This remote attack can put a server into a Denial of Service (DoS) state, but remote code execution is not of concern. The vulnerability roots on the flaws in the TCP Selective Acknowledgement (SACK) and Maximum Segment Size (MSS) implementation. The attack can be triggered by a remote user who sets the MSS to the lowest limit of 48 bytes and sends a sequence of specially crafted SACK packets to overflow the receiver’s socket buffer. Most of the Linux distributions have released a patch, RedHat,
Unit42
TCP SACK Panics Linux Servers
blogs_unit42·2019-06-21·CVSS 7.5
CVE-2019-11477 [HIGH] TCP SACK Panics Linux Servers
Threat Research Center
Threat Research
Cloud Cybersecurity Research
## TCP SACK Panics Linux Servers
Unit 42
Published: June 21, 2019
Cloud Cybersecurity Research
Threat Research
Vulnerabilities
AWS
Azure
CVE-2019-11477
CVE-2019-11478
CVE-2019-11479
GCP
Linux
Public cloud
SACK
## Executive Summary
The newly discovered Linux vulnerabilities , CVE-2019-11477 , CVE-2019-11478 , and CVE-2019-11479 , affect all Linux operating systems newer than kernel 2.6.29 (released on March 2009) or above and can cause a kernel panic to systems with services listening on a TCP connection. This remote attack can put a server into a Denial of Service (DoS) state, but remote code execution is not of concern. The vulnerability roots on the flaws in the TCP Selective Acknowledgement (SACK)
Tenable
SACK Panic: Linux and FreeBSD Kernels Vulnerable to Remote Denial of Service Vulnerabilities (CVE-2019-11477)
blogs_tenable·2019-06-18·CVSS 7.5
[HIGH] SACK Panic: Linux and FreeBSD Kernels Vulnerable to Remote Denial of Service Vulnerabilities (CVE-2019-11477)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bugzilla
CVE-2019-11478 kernel: tcp: excessive resource consumption while processing SACK blocks allows remote denial of service [fedora-all]
bugzilla·2019-06-17·CVSS 5.3
CVE-2019-11478 [MEDIUM] CVE-2019-11478 kernel: tcp: excessive resource consumption while processing SACK blocks allows remote denial of service [fedora-all]
CVE-2019-11478 kernel: tcp: excessive resource consumption while processing SACK blocks allows remote denial of service [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message
Bugzilla
CVE-2019-11478 Kernel: tcp: excessive resource consumption while processing SACK blocks allows remote denial of service
bugzilla·2019-06-11·CVSS 5.3
CVE-2019-11478 [MEDIUM] CVE-2019-11478 Kernel: tcp: excessive resource consumption while processing SACK blocks allows remote denial of service
CVE-2019-11478 Kernel: tcp: excessive resource consumption while processing SACK blocks allows remote denial of service
An excessive resource(CPU/Memory etc.) consumption issue was found in the way
Linux kernel processes TCP Selective Acknowledgement(SACK) segments. While
processing SACK segments, Linux kernel's socket buffer(SBK) data structure
becomes fragmented. SKB is also used as retransmission queue. This fragmentation
leads to increased resource utilisation to traverse and process these fragments,
as further SACK segments are received on the same TCP connection.
A remote attacker could use this flaw to cause a DoS by sending a crafted
sequence of SACK segments on a TCP connection.
Upstream patch:
-> https://git.kernel.org/pub/scm/linux/kernel/git/davem/net.git/commit/?id=f070ef2a
http://packetstormsecurity.com/files/153346/Kernel-Live-Patch-Security-Notice-LSN-0052-1.htmlhttp://packetstormsecurity.com/files/154408/Kernel-Live-Patch-Security-Notice-LSN-0055-1.htmlhttp://packetstormsecurity.com/files/154951/Kernel-Live-Patch-Security-Notice-LSN-0058-1.htmlhttp://www.arubanetworks.com/assets/alert/ARUBA-PSA-2020-010.txthttp://www.openwall.com/lists/oss-security/2019/06/28/2http://www.openwall.com/lists/oss-security/2019/07/06/3http://www.openwall.com/lists/oss-security/2019/07/06/4http://www.openwall.com/lists/oss-security/2019/10/24/1http://www.openwall.com/lists/oss-security/2019/10/29/3http://www.vmware.com/security/advisories/VMSA-2019-0010.htmlhttps://access.redhat.com/errata/RHSA-2019:1594https://access.redhat.com/errata/RHSA-2019:1602https://access.redhat.com/errata/RHSA-2019:1699https://access.redhat.com/security/vulnerabilities/tcpsackhttps://cert-portal.siemens.com/productcert/pdf/ssa-462066.pdfhttps://git.kernel.org/pub/scm/linux/kernel/git/davem/net.git/commit/?id=f070ef2ac66716357066b683fb0baf55f8191a2ehttps://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-001.mdhttps://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44193https://kc.mcafee.com/corporate/index?page=content&id=SB10287https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2019-0007https://seclists.org/bugtraq/2019/Jul/30https://security.netapp.com/advisory/ntap-20190625-0001/https://support.f5.com/csp/article/K26618426https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/SACKPanichttps://www.kb.cert.org/vuls/id/905115https://www.oracle.com/security-alerts/cpujan2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttps://www.synology.com/security/advisory/Synology_SA_19_28https://www.us-cert.gov/ics/advisories/icsa-19-253-03http://packetstormsecurity.com/files/153346/Kernel-Live-Patch-Security-Notice-LSN-0052-1.htmlhttp://packetstormsecurity.com/files/154408/Kernel-Live-Patch-Security-Notice-LSN-0055-1.htmlhttp://packetstormsecurity.com/files/154951/Kernel-Live-Patch-Security-Notice-LSN-0058-1.htmlhttp://www.arubanetworks.com/assets/alert/ARUBA-PSA-2020-010.txthttp://www.openwall.com/lists/oss-security/2019/06/28/2http://www.openwall.com/lists/oss-security/2019/07/06/3http://www.openwall.com/lists/oss-security/2019/07/06/4http://www.openwall.com/lists/oss-security/2019/10/24/1http://www.openwall.com/lists/oss-security/2019/10/29/3http://www.vmware.com/security/advisories/VMSA-2019-0010.htmlhttps://access.redhat.com/errata/RHSA-2019:1594https://access.redhat.com/errata/RHSA-2019:1602https://access.redhat.com/errata/RHSA-2019:1699https://access.redhat.com/security/vulnerabilities/tcpsackhttps://cert-portal.siemens.com/productcert/pdf/ssa-462066.pdfhttps://git.kernel.org/pub/scm/linux/kernel/git/davem/net.git/commit/?id=f070ef2ac66716357066b683fb0baf55f8191a2ehttps://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-001.mdhttps://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44193https://kc.mcafee.com/corporate/index?page=content&id=SB10287https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2019-0007https://seclists.org/bugtraq/2019/Jul/30https://security.netapp.com/advisory/ntap-20190625-0001/https://support.f5.com/csp/article/K26618426https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/SACKPanichttps://www.kb.cert.org/vuls/id/905115https://www.oracle.com/security-alerts/cpujan2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttps://www.synology.com/security/advisory/Synology_SA_19_28https://www.us-cert.gov/ics/advisories/icsa-19-253-03
2019-06-19
Published