CVE-2019-11479
published 2019-06-19CVE-2019-11479: Jonathan Looney discovered that the Linux kernel default MSS is hard-coded to 48 bytes. This allows a remote peer to fragment TCP resend queues significantly…
PriorityP261high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
91.66%
99.8th percentile
Jonathan Looney discovered that the Linux kernel default MSS is hard-coded to 48 bytes. This allows a remote peer to fragment TCP resend queues significantly more than if a larger MSS were enforced. A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11, and is fixed in commits 967c05aee439e6e5d7d805e195b3a20ef5c433d6 and 5f3e2bf008c2221478101ee72f5cb4654b9fc363.
Affected
102 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | linux | < linux 4.19.37-4 (bookworm) | linux 4.19.37-4 (bookworm) |
| f5 | big-ip_access_policy_manager | >= 11.5.2 < 11.6.5.1 | 11.6.5.1 |
| f5 | big-ip_access_policy_manager | >= 12.1.0 < 12.1.5.1 | 12.1.5.1 |
| f5 | big-ip_access_policy_manager | >= 13.1.0 < 13.1.3.2 | 13.1.3.2 |
| f5 | big-ip_access_policy_manager | >= 14.0.0 < 14.0.1.1 | 14.0.1.1 |
| f5 | big-ip_access_policy_manager | >= 14.1.2 < 14.1.2.1 | 14.1.2.1 |
| f5 | big-ip_access_policy_manager | >= 15.0.0 < 15.0.1.1 | 15.0.1.1 |
| f5 | big-ip_advanced_firewall_manager | >= 11.5.2 < 11.6.5.1 | 11.6.5.1 |
| f5 | big-ip_advanced_firewall_manager | >= 12.1.0 < 12.1.5.1 | 12.1.5.1 |
| f5 | big-ip_advanced_firewall_manager | >= 13.1.0 < 13.1.3.2 | 13.1.3.2 |
| f5 | big-ip_advanced_firewall_manager | >= 14.0.0 < 14.0.1.1 | 14.0.1.1 |
| f5 | big-ip_advanced_firewall_manager | >= 14.1.2 < 14.1.2.1 | 14.1.2.1 |
| f5 | big-ip_advanced_firewall_manager | >= 15.0.0 < 15.0.1.1 | 15.0.1.1 |
| f5 | big-ip_analytics | >= 11.5.2 < 11.6.5.1 | 11.6.5.1 |
| f5 | big-ip_analytics | >= 12.1.0 < 12.1.5.1 | 12.1.5.1 |
| f5 | big-ip_analytics | >= 13.1.0 < 13.1.3.2 | 13.1.3.2 |
| f5 | big-ip_analytics | >= 14.0.0 < 14.0.1.1 | 14.0.1.1 |
| f5 | big-ip_analytics | >= 14.1.2 < 14.1.2.1 | 14.1.2.1 |
| f5 | big-ip_analytics | >= 15.0.0 < 15.0.1.1 | 15.0.1.1 |
| f5 | big-ip_application_acceleration_manager | >= 11.5.2 < 11.6.5.1 | 11.6.5.1 |
Detection & IOCsextracted from sources · hover to see the quote
- →Alert on sustained maximum CPU/bandwidth resource consumption on Linux hosts receiving TCP connections with low MSS values, as this indicates active exploitation causing excess resource consumption. ↗
- →Apply firewall rules or traffic control policies to block TCP connections advertising MSS=48 as an immediate mitigation where patching is not possible. ↗
- ·The Linux kernel default MSS is hard-coded to 48 bytes, which is the root configuration weakness enabling this attack. Patched stable kernel releases are 4.4.182, 4.9.182, 4.14.127, 4.19.52, and 5.1.11. ↗
- ·All Linux kernels version 2.6.29 and above are vulnerable. Kernel branches outside of 3.16.y (unmaintained) and all EOL branches require mitigation via firewall/tc rules if patching is not feasible. ↗
- ·The Ubuntu patch for USN-4017-1 introduced a regression affecting networking applications that set very low SO_SNDBUF values; USN-4041-1 supersedes it and must be applied instead. ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-99cq-xr7g-h22w: Jonathan Looney discovered that the Linux kernel default MSS is hard-coded to 48 bytes
ghsa_unreviewed·2022-05-24
CVE-2019-11479 [HIGH] CWE-405 GHSA-99cq-xr7g-h22w: Jonathan Looney discovered that the Linux kernel default MSS is hard-coded to 48 bytes
Jonathan Looney discovered that the Linux kernel default MSS is hard-coded to 48 bytes. This allows a remote peer to fragment TCP resend queues significantly more than if a larger MSS were enforced. A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11, and is fixed in commits 967c05aee439e6e5d7d805e195b3a20ef5c433d6 and 5f3e2bf008c2221478101ee72f5cb4654b9fc363.
OSV
linux-lts-xenial, linux-aws, linux-azure update
osv·2019-06-29·CVSS 7.5
[HIGH] linux-lts-xenial, linux-aws, linux-azure update
linux-lts-xenial, linux-aws, linux-azure update
USN-4041-1 provided updates for the Linux kernel in Ubuntu.
This update provides the corresponding updates for the Linux kernel
for Ubuntu 16.04 ESM.
USN-4017-2 fixed vulnerabilities in the Linux kernel. Unfortunately,
the update introduced a regression that interfered with networking
applications that setup very low SO_SNDBUF values. This update fixes
the problem.
We apologize for the inconvenience.
Jonathan Looney discovered that the Linux kernel could be coerced into
segmenting responses into multiple TCP segments. A remote attacker could
construct an ongoing sequence of requests to cause a denial of service.
(CVE-2019-11479)
OSV
CVE-2019-11479: Jonathan Looney discovered that the Linux kernel default MSS is hard-coded to 48 bytes
osv·2019-06-19·CVSS 7.5
CVE-2019-11479 [HIGH] CVE-2019-11479: Jonathan Looney discovered that the Linux kernel default MSS is hard-coded to 48 bytes
Jonathan Looney discovered that the Linux kernel default MSS is hard-coded to 48 bytes. This allows a remote peer to fragment TCP resend queues significantly more than if a larger MSS were enforced. A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11, and is fixed in commits 967c05aee439e6e5d7d805e195b3a20ef5c433d6 and 5f3e2bf008c2221478101ee72f5cb4654b9fc363.
Kernel
tcp: enforce tcp_min_snd_mss in tcp_mtu_probing()
kernel_security·2019-06-08·CVSS 7.5
CVE-2019-11479 [HIGH] tcp: enforce tcp_min_snd_mss in tcp_mtu_probing()
tcp: enforce tcp_min_snd_mss in tcp_mtu_probing()
If mtu probing is enabled tcp_mtu_probing() could very well end up
with a too small MSS.
Use the new sysctl tcp_min_snd_mss to make sure MSS search
is performed in an acceptable range.
CVE-2019-11479 -- tcp mss hardcoded to 48
Signed-off-by: Eric Dumazet
Reported-by: Jonathan Lemon
Cc: Jonathan Looney
Acked-by: Neal Cardwell
Cc: Yuchung Cheng
Cc: Tyler Hicks
Cc: Bruce Curtis
Signed-off-by: David S. Miller
Kernel
tcp: add tcp_min_snd_mss sysctl
kernel_security·2019-06-06·CVSS 7.5
CVE-2019-11479 [HIGH] tcp: add tcp_min_snd_mss sysctl
tcp: add tcp_min_snd_mss sysctl
Some TCP peers announce a very small MSS option in their SYN and/or
SYN/ACK messages.
This forces the stack to send packets with a very high network/cpu
overhead.
Linux has enforced a minimal value of 48. Since this value includes
the size of TCP options, and that the options can consume up to 40
bytes, this means that each segment can include only 8 bytes of payload.
In some cases, it can be useful to increase the minimal value
to a saner value.
We still let the default to 48 (TCP_MIN_SND_MSS), for compatibility
reasons.
Note that TCP_MAXSEG socket option enforces a minimal value
of (TCP_MIN_MSS). David Miller increased this minimal value
in commit c39508d6f118 ("tcp: Make TCP_MAXSEG minimum more correct.")
from 64 to 88.
We might in the future merge
CISA ICS
Siemens Industrial Products (Update R)
cisa_ics·2022-05-12·CVSS 7.5
[HIGH] Siemens Industrial Products (Update R)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens Industrial Products (Update R)
Last RevisedMay 12, 2022
Alert CodeICSA-19-253-03
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.5
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: Industrial Products
- Vulnerabilities: Excessive Data Query Operations in a Large Data Table, Integer Overflow or Wraparound, Uncontrolled Resource Consumption
## 2. UPDATE INFORMATION
This updated advisory is a follow-up to the advisory update titled ICSA-19-253-04 Siemens Industrial Products (Update Q) published on April 14, 2022 to the ICS webpage on cisa.gov/
Ubuntu
Linux kernel update
vendor_ubuntu·2019-06-29
CVE-2019-11479 Linux kernel update
Title: Linux kernel update
Summary: Several security issues were fixed in the Linux kernel.
USN-4017-1 fixed vulnerabilities in the Linux kernel for Ubuntu.
Unfortunately, the update introduced a regression that interfered with
networking applications that setup very low SO_SNDBUF values. This
update fixes the problem.
We apologize for the inconvenience.
Jonathan Looney discovered that the Linux kernel could be coerced into
segmenting responses into multiple TCP segments. A remote attacker could
construct an ongoing sequence of requests to cause a denial of service.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which r
Ubuntu
Linux kernel (HWE) update
vendor_ubuntu·2019-06-29·CVSS 7.5
CVE-2019-11479 [HIGH] Linux kernel (HWE) update
Title: Linux kernel (HWE) update
Summary: Several security issues were fixed in the Linux kernel.
USN-4041-1 provided updates for the Linux kernel in Ubuntu.
This update provides the corresponding updates for the Linux kernel
for Ubuntu 16.04 ESM.
USN-4017-2 fixed vulnerabilities in the Linux kernel. Unfortunately,
the update introduced a regression that interfered with networking
applications that setup very low SO_SNDBUF values. This update fixes
the problem.
We apologize for the inconvenience.
Jonathan Looney discovered that the Linux kernel could be coerced into
segmenting responses into multiple TCP segments. A remote attacker could
construct an ongoing sequence of requests to cause a denial of service.
(CVE-2019-11479)
Instructions: After a standard system update you need to re
Palo Alto
PAN-SA-2019-0013 Information about TCP SACK Panic Findings in PAN-OS
vendor_paloalto·2019-06-27·CVSS 7.5
CVE-2019-11477 [HIGH] CWE-190 PAN-SA-2019-0013 Information about TCP SACK Panic Findings in PAN-OS
PAN-SA-2019-0013 Information about TCP SACK Panic Findings in PAN-OS
Palo Alto Networks is aware of recent vulnerability disclosures known as TCP SACK Panic vulnerabilities. (Ref: PAN-119745/ CVE-2019-11477, CVE-2019-11478, CVE-2019-11479) Successful
CVEs: CVE-2019-11477, CVE-2019-11478, CVE-2019-11479, CVE-2019-5599
Affected products: GlobalProtect, PAN-OS
Red Hat
kernel: tcp: excessive resource consumption for TCP connections with low MSS allows remote denial of service
vendor_redhat·2019-06-17·CVSS 7.5
CVE-2019-11479 [HIGH] CWE-400 kernel: tcp: excessive resource consumption for TCP connections with low MSS allows remote denial of service
kernel: tcp: excessive resource consumption for TCP connections with low MSS allows remote denial of service
Jonathan Looney discovered that the Linux kernel default MSS is hard-coded to 48 bytes. This allows a remote peer to fragment TCP resend queues significantly more than if a larger MSS were enforced. A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11, and is fixed in commits 967c05aee439e6e5d7d805e195b3a20ef5c433d6 and 5f3e2bf008c2221478101ee72f5cb4654b9fc363.
An excessive resource consumption flaw was found in the way the Linux kernel's networking subsystem processed TCP segments. If the Maximum Segment Size (MSS) of a TCP connection was set to low values, such as 48 bytes, it can
Debian
CVE-2019-11479: linux - Jonathan Looney discovered that the Linux kernel default MSS is hard-coded to 48...
vendor_debian·2019·CVSS 7.5
CVE-2019-11479 [HIGH] CVE-2019-11479: linux - Jonathan Looney discovered that the Linux kernel default MSS is hard-coded to 48...
Jonathan Looney discovered that the Linux kernel default MSS is hard-coded to 48 bytes. This allows a remote peer to fragment TCP resend queues significantly more than if a larger MSS were enforced. A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11, and is fixed in commits 967c05aee439e6e5d7d805e195b3a20ef5c433d6 and 5f3e2bf008c2221478101ee72f5cb4654b9fc363.
Scope: local
bookworm: resolved (fixed in 4.19.37-4)
bullseye: resolved (fixed in 4.19.37-4)
forky: resolved (fixed in 4.19.37-4)
sid: resolved (fixed in 4.19.37-4)
trixie: resolved (fixed in 4.19.37-4)
No detection rules found.
No public exploits indexed.
Qualys
July 2019 Patch Tuesday – 77 Vulns, 15 Critical, DHCP RCE, Exploited PrivEsc, SQL, Adobe Vulns | Qualys
blogs_qualys·2019-07-09·CVSS 9.8
[CRITICAL] July 2019 Patch Tuesday – 77 Vulns, 15 Critical, DHCP RCE, Exploited PrivEsc, SQL, Adobe Vulns | Qualys
This month’s Microsoft Patch Tuesday addresses 77 vulnerabilities with 15 of them labeled as Critical. Of the 15 Critical vulns, 11 are for scripting engines and browsers, with the remaining four covering DHCP Server, GDI+, .NET Framework, and Azure DevOps Server / Team Foundation Server. In addition, Microsoft has released Important patches for two actively exploited privilege escalation vulnerabilities, as well as a SQL Server RCE. Microsoft also issued two advisories for Outlook on the web and Linux Kernel vulnerabilities. Adobe issued patches today for Bridge CC, Experience Manager, and Dreamweaver.
### Workstation Patches
Scripting Engine, Browser, GDI+, and .NET Framework patches should be prioritized for workstation-type devices, meaning any system that is used for email or to acc
Qualys
July 2019 Patch Tuesday – 77 Vulns, 15 Critical, DHCP RCE, Exploited PrivEsc, SQL, Adobe Vulns
blogs_qualys·2019-07-09·CVSS 9.8
[CRITICAL] July 2019 Patch Tuesday – 77 Vulns, 15 Critical, DHCP RCE, Exploited PrivEsc, SQL, Adobe Vulns
This month’s Microsoft Patch Tuesday addresses 77 vulnerabilities with 15 of them labeled as Critical. Of the 15 Critical vulns, 11 are for scripting engines and browsers, with the remaining four covering DHCP Server, GDI+, .NET Framework, and Azure DevOps Server / Team Foundation Server. In addition, Microsoft has released Important patches for two actively exploited privilege escalation vulnerabilities, as well as a SQL Server RCE. Microsoft also issued two advisories for Outlook on the web and Linux Kernel vulnerabilities. Adobe issued patches today for Bridge CC, Experience Manager, and Dreamweaver.
## Workstation Patches
Scripting Engine, Browser, GDI+, and .NET Framework patches should be prioritized for workstation-type devices, meaning any system that is used for email or to acce
Unit42
TCP SACK Panics Linux Servers
blogs_unit42·2019-06-21·CVSS 7.5
CVE-2019-11477 [HIGH] TCP SACK Panics Linux Servers
#### Executive Summary
The newly discovered Linux vulnerabilities, CVE-2019-11477, CVE-2019-11478, and CVE-2019-11479, affect all Linux operating systems newer than kernel 2.6.29 (released on March 2009) or above and can cause a kernel panic to systems with services listening on a TCP connection. This remote attack can put a server into a Denial of Service (DoS) state, but remote code execution is not of concern. The vulnerability roots on the flaws in the TCP Selective Acknowledgement (SACK) and Maximum Segment Size (MSS) implementation. The attack can be triggered by a remote user who sets the MSS to the lowest limit of 48 bytes and sends a sequence of specially crafted SACK packets to overflow the receiver’s socket buffer. Most of the Linux distributions have released a patch, RedHat,
Unit42
TCP SACK Panics Linux Servers
blogs_unit42·2019-06-21·CVSS 7.5
CVE-2019-11477 [HIGH] TCP SACK Panics Linux Servers
Threat Research Center
Threat Research
Cloud Cybersecurity Research
## TCP SACK Panics Linux Servers
Unit 42
Published: June 21, 2019
Cloud Cybersecurity Research
Threat Research
Vulnerabilities
AWS
Azure
CVE-2019-11477
CVE-2019-11478
CVE-2019-11479
GCP
Linux
Public cloud
SACK
## Executive Summary
The newly discovered Linux vulnerabilities , CVE-2019-11477 , CVE-2019-11478 , and CVE-2019-11479 , affect all Linux operating systems newer than kernel 2.6.29 (released on March 2009) or above and can cause a kernel panic to systems with services listening on a TCP connection. This remote attack can put a server into a Denial of Service (DoS) state, but remote code execution is not of concern. The vulnerability roots on the flaws in the TCP Selective Acknowledgement (SACK)
Tenable
SACK Panic: Linux and FreeBSD Kernels Vulnerable to Remote Denial of Service Vulnerabilities (CVE-2019-11477)
blogs_tenable·2019-06-18·CVSS 7.5
[HIGH] SACK Panic: Linux and FreeBSD Kernels Vulnerable to Remote Denial of Service Vulnerabilities (CVE-2019-11477)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bugzilla
CVE-2019-11479 kernel: tcp: excessive resource consumption for TCP connections with low MSS allows remote denial of service [fedora-all]
bugzilla·2019-06-17·CVSS 7.5
CVE-2019-11479 [HIGH] CVE-2019-11479 kernel: tcp: excessive resource consumption for TCP connections with low MSS allows remote denial of service [fedora-all]
CVE-2019-11479 kernel: tcp: excessive resource consumption for TCP connections with low MSS allows remote denial of service [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit mes
Bugzilla
CVE-2019-11479 kernel: tcp: excessive resource consumption for TCP connections with low MSS allows remote denial of service
bugzilla·2019-06-11·CVSS 7.5
CVE-2019-11479 [HIGH] CVE-2019-11479 kernel: tcp: excessive resource consumption for TCP connections with low MSS allows remote denial of service
CVE-2019-11479 kernel: tcp: excessive resource consumption for TCP connections with low MSS allows remote denial of service
An excessive resource consumption issue was found in the way
Linux kernel processes TCP segments. If Maximum Segment Size(MSS) of a TCP
connection was set to its lowest value of 48 bytes, it leaves merely 8 bytes for
the user data. It significantly increases Linux kernel's resource
(CPU/Memory/Bandwidth etc.) utilisation leading to a DoS like scenario.
A remote attacker could use this flaw to cause DoS by repeatedly sending network
traffic on a TCP connection with lowest value for TCP MSS.
Upstream patch:
-> https://git.kernel.org/pub/scm/linux/kernel/git/davem/net.git/commit/?id=967c05aee439e6e5d7d805e195b3a20ef5c433d6
Discussion:
Acknowledgments:
Name: Jonatha
http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2020-010.txthttp://www.openwall.com/lists/oss-security/2019/06/28/2http://www.openwall.com/lists/oss-security/2019/07/06/3http://www.openwall.com/lists/oss-security/2019/07/06/4http://www.securityfocus.com/bid/108818https://access.redhat.com/errata/RHSA-2019:1594https://access.redhat.com/errata/RHSA-2019:1602https://access.redhat.com/errata/RHSA-2019:1699https://access.redhat.com/security/vulnerabilities/tcpsackhttps://cert-portal.siemens.com/productcert/pdf/ssa-462066.pdfhttps://git.kernel.org/pub/scm/linux/kernel/git/davem/net.git/commit/?id=5f3e2bf008c2221478101ee72f5cb4654b9fc363https://git.kernel.org/pub/scm/linux/kernel/git/davem/net.git/commit/?id=967c05aee439e6e5d7d805e195b3a20ef5c433d6https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-001.mdhttps://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44193https://kc.mcafee.com/corporate/index?page=content&id=SB10287https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2019-0008https://security.netapp.com/advisory/ntap-20190625-0001/https://support.f5.com/csp/article/K35421172https://support.f5.com/csp/article/K35421172?utm_source=f5support&%3Butm_medium=RSShttps://usn.ubuntu.com/4041-1/https://usn.ubuntu.com/4041-2/https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/SACKPanichttps://www.kb.cert.org/vuls/id/905115https://www.oracle.com/security-alerts/cpujan2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttps://www.synology.com/security/advisory/Synology_SA_19_28https://www.us-cert.gov/ics/advisories/icsa-19-253-03https://www.us-cert.gov/ics/advisories/icsma-20-170-06http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2020-010.txthttp://www.openwall.com/lists/oss-security/2019/06/28/2http://www.openwall.com/lists/oss-security/2019/07/06/3http://www.openwall.com/lists/oss-security/2019/07/06/4http://www.securityfocus.com/bid/108818https://access.redhat.com/errata/RHSA-2019:1594https://access.redhat.com/errata/RHSA-2019:1602https://access.redhat.com/errata/RHSA-2019:1699https://access.redhat.com/security/vulnerabilities/tcpsackhttps://cert-portal.siemens.com/productcert/pdf/ssa-462066.pdfhttps://git.kernel.org/pub/scm/linux/kernel/git/davem/net.git/commit/?id=5f3e2bf008c2221478101ee72f5cb4654b9fc363https://git.kernel.org/pub/scm/linux/kernel/git/davem/net.git/commit/?id=967c05aee439e6e5d7d805e195b3a20ef5c433d6https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-001.mdhttps://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44193https://kc.mcafee.com/corporate/index?page=content&id=SB10287https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2019-0008https://security.netapp.com/advisory/ntap-20190625-0001/https://support.f5.com/csp/article/K35421172https://support.f5.com/csp/article/K35421172?utm_source=f5support&%3Butm_medium=RSShttps://usn.ubuntu.com/4041-1/https://usn.ubuntu.com/4041-2/https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/SACKPanichttps://www.kb.cert.org/vuls/id/905115https://www.oracle.com/security-alerts/cpujan2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttps://www.synology.com/security/advisory/Synology_SA_19_28https://www.us-cert.gov/ics/advisories/icsa-19-253-03https://www.us-cert.gov/ics/advisories/icsma-20-170-06
2019-06-19
Published