cbcvebase.
CVE-2019-11479
published 2019-06-19

CVE-2019-11479: Jonathan Looney discovered that the Linux kernel default MSS is hard-coded to 48 bytes. This allows a remote peer to fragment TCP resend queues significantly…

PriorityP261high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
91.66%
99.8th percentile
Jonathan Looney discovered that the Linux kernel default MSS is hard-coded to 48 bytes. This allows a remote peer to fragment TCP resend queues significantly more than if a larger MSS were enforced. A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11, and is fixed in commits 967c05aee439e6e5d7d805e195b3a20ef5c433d6 and 5f3e2bf008c2221478101ee72f5cb4654b9fc363.

Affected

102 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debianlinux< linux 4.19.37-4 (bookworm)linux 4.19.37-4 (bookworm)
f5big-ip_access_policy_manager>= 11.5.2 < 11.6.5.111.6.5.1
f5big-ip_access_policy_manager>= 12.1.0 < 12.1.5.112.1.5.1
f5big-ip_access_policy_manager>= 13.1.0 < 13.1.3.213.1.3.2
f5big-ip_access_policy_manager>= 14.0.0 < 14.0.1.114.0.1.1
f5big-ip_access_policy_manager>= 14.1.2 < 14.1.2.114.1.2.1
f5big-ip_access_policy_manager>= 15.0.0 < 15.0.1.115.0.1.1
f5big-ip_advanced_firewall_manager>= 11.5.2 < 11.6.5.111.6.5.1
f5big-ip_advanced_firewall_manager>= 12.1.0 < 12.1.5.112.1.5.1
f5big-ip_advanced_firewall_manager>= 13.1.0 < 13.1.3.213.1.3.2
f5big-ip_advanced_firewall_manager>= 14.0.0 < 14.0.1.114.0.1.1
f5big-ip_advanced_firewall_manager>= 14.1.2 < 14.1.2.114.1.2.1
f5big-ip_advanced_firewall_manager>= 15.0.0 < 15.0.1.115.0.1.1
f5big-ip_analytics>= 11.5.2 < 11.6.5.111.6.5.1
f5big-ip_analytics>= 12.1.0 < 12.1.5.112.1.5.1
f5big-ip_analytics>= 13.1.0 < 13.1.3.213.1.3.2
f5big-ip_analytics>= 14.0.0 < 14.0.1.114.0.1.1
f5big-ip_analytics>= 14.1.2 < 14.1.2.114.1.2.1
f5big-ip_analytics>= 15.0.0 < 15.0.1.115.0.1.1
f5big-ip_application_acceleration_manager>= 11.5.2 < 11.6.5.111.6.5.1

Detection & IOCsextracted from sources · hover to see the quote

hash967c05aee439e6e5d7d805e195b3a20ef5c433d6
hash5f3e2bf008c2221478101ee72f5cb4654b9fc363
filenamePATCH_net_3_4.patch
filenamePATCH_net_4_4.patch
  • Alert on sustained maximum CPU/bandwidth resource consumption on Linux hosts receiving TCP connections with low MSS values, as this indicates active exploitation causing excess resource consumption.
  • Apply firewall rules or traffic control policies to block TCP connections advertising MSS=48 as an immediate mitigation where patching is not possible.
  • ·The Linux kernel default MSS is hard-coded to 48 bytes, which is the root configuration weakness enabling this attack. Patched stable kernel releases are 4.4.182, 4.9.182, 4.14.127, 4.19.52, and 5.1.11.
  • ·All Linux kernels version 2.6.29 and above are vulnerable. Kernel branches outside of 3.16.y (unmaintained) and all EOL branches require mitigation via firewall/tc rules if patching is not feasible.
  • ·The Ubuntu patch for USN-4017-1 introduced a regression affecting networking applications that set very low SO_SNDBUF values; USN-4041-1 supersedes it and must be applied instead.

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.