CVE-2019-11683
published 2019-05-02CVE-2019-11683: udp_gro_receive_segment in net/ipv4/udp_offload.c in the Linux kernel 5.x before 5.0.13 allows remote attackers to cause a denial of service…
PriorityP347critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
7.07%
93.5th percentile
udp_gro_receive_segment in net/ipv4/udp_offload.c in the Linux kernel 5.x before 5.0.13 allows remote attackers to cause a denial of service (slab-out-of-bounds memory corruption) or possibly have unspecified other impact via UDP packets with a 0 payload, because of mishandling of padded packets, aka the "GRO packet of death" issue.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| debian | linux | — | — |
| linux | linux_kernel | >= 5.0 < 5.0.13 | 5.0.13 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv9.8CRITICAL
vendor_debian9.8LOW
vendor_redhat9.8CRITICAL
vendor_ubuntu5.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v8g2-q4cj-f9mh: udp_gro_receive_segment in net/ipv4/udp_offload
ghsa_unreviewed·2022-05-24
CVE-2019-11683 [CRITICAL] CWE-787 GHSA-v8g2-q4cj-f9mh: udp_gro_receive_segment in net/ipv4/udp_offload
udp_gro_receive_segment in net/ipv4/udp_offload.c in the Linux kernel 5.x through 5.0.11 allows remote attackers to cause a denial of service (slab-out-of-bounds memory corruption) or possibly have unspecified other impact via UDP packets with a 0 payload, because of mishandling of padded packets, aka the "GRO packet of death" issue.
OSV
CVE-2019-11683: udp_gro_receive_segment in net/ipv4/udp_offload
osv·2019-05-02·CVSS 9.8
CVE-2019-11683 [CRITICAL] CVE-2019-11683: udp_gro_receive_segment in net/ipv4/udp_offload
udp_gro_receive_segment in net/ipv4/udp_offload.c in the Linux kernel 5.x before 5.0.13 allows remote attackers to cause a denial of service (slab-out-of-bounds memory corruption) or possibly have unspecified other impact via UDP packets with a 0 payload, because of mishandling of padded packets, aka the "GRO packet of death" issue.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2019-05-14·CVSS 5.6
CVE-2019-11683 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Ke Sun, Henrique Kawakami, Kekai Hu, Rodrigo Branco, Giorgi Maisuradze, Dan
Horea Lutas, Andrei Lutas, Volodymyr Pikhur, Stephan van Schaik, Alyssa
Milburn, Sebastian Österlund, Pietro Frigo, Kaveh Razavi, Herbert Bos,
Cristiano Giuffrida, Moritz Lipp, Michael Schwarz, and Daniel Gruss
discovered that memory previously stored in microarchitectural fill buffers
of an Intel CPU core may be exposed to a malicious process that is
executing on the same CPU core. A local attacker could use this to expose
sensitive information. (CVE-2018-12130)
Brandon Falk, Ke Sun, Henrique Kawakami, Kekai Hu, Rodrigo Branco, Stephan
van Schaik, Alyssa Milburn, Sebastian Österlund, Pietro Frigo, Kaveh
Razavi,
Red Hat
kernel: udp_gro_receive_segment in net/ipv4/udp_offload.c allows denial of service or other unspecified impact via UDP packets with 0 payload
vendor_redhat·2019-05-01·CVSS 9.8
CVE-2019-11683 [CRITICAL] CWE-119 kernel: udp_gro_receive_segment in net/ipv4/udp_offload.c allows denial of service or other unspecified impact via UDP packets with 0 payload
kernel: udp_gro_receive_segment in net/ipv4/udp_offload.c allows denial of service or other unspecified impact via UDP packets with 0 payload
udp_gro_receive_segment in net/ipv4/udp_offload.c in the Linux kernel 5.x before 5.0.13 allows remote attackers to cause a denial of service (slab-out-of-bounds memory corruption) or possibly have unspecified other impact via UDP packets with a 0 payload, because of mishandling of padded packets, aka the "GRO packet of death" issue.
Statement: This flaw did not affect the versions of kernel as shipped with Red Hat Enterprise Linux 5, 6, 7 and 8.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-alt (R
Debian
CVE-2019-11683: linux - udp_gro_receive_segment in net/ipv4/udp_offload.c in the Linux kernel 5.x before...
vendor_debian·2019·CVSS 9.8
CVE-2019-11683 [CRITICAL] CVE-2019-11683: linux - udp_gro_receive_segment in net/ipv4/udp_offload.c in the Linux kernel 5.x before...
udp_gro_receive_segment in net/ipv4/udp_offload.c in the Linux kernel 5.x before 5.0.13 allows remote attackers to cause a denial of service (slab-out-of-bounds memory corruption) or possibly have unspecified other impact via UDP packets with a 0 payload, because of mishandling of padded packets, aka the "GRO packet of death" issue.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-11683 kernel: udp_gro_receive_segment in net/ipv4/udp_offload.c allows denial of service or other unspecified impact via UDP packets with 0 payload
bugzilla·2019-05-07·CVSS 9.8
CVE-2019-11683 [CRITICAL] CVE-2019-11683 kernel: udp_gro_receive_segment in net/ipv4/udp_offload.c allows denial of service or other unspecified impact via UDP packets with 0 payload
CVE-2019-11683 kernel: udp_gro_receive_segment in net/ipv4/udp_offload.c allows denial of service or other unspecified impact via UDP packets with 0 payload
udp_gro_receive_segment in net/ipv4/udp_offload.c in the Linux kernel 5.x through 5.0.11 allows remote attackers to cause a denial of service (slab-out-of-bounds memory corruption) or possibly have unspecified other impact via UDP packets with a 0 payload, because of mishandling of padded packets, aka the "GRO packet of death" issue.
Introduced in:
http://git.kernel.org/linus/e20cf8d3f1f763ad28a9cb3b41305b8a8a42653e
Upstream patch:
https://git.kernel.org/pub/scm/linux/kernel/git/davem/net.git/commit/?id=4dd2b82d5adfbe0b1587ccad7a8f76d826120f37
References:
https://www.spinics.net/lists/netdev/msg568315.html
http://www.openwall.co
Bugzilla
CVE-2019-11683 kernel: udp_gro_receive_segment in net/ipv4/udp_offload.c allows denial of service or other unspecified impact via UDP packets with 0 payload [fedora-all]
bugzilla·2019-05-07·CVSS 9.8
CVE-2019-11683 [CRITICAL] CVE-2019-11683 kernel: udp_gro_receive_segment in net/ipv4/udp_offload.c allows denial of service or other unspecified impact via UDP packets with 0 payload [fedora-all]
CVE-2019-11683 kernel: udp_gro_receive_segment in net/ipv4/udp_offload.c allows denial of service or other unspecified impact via UDP packets with 0 payload [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM ch
http://www.openwall.com/lists/oss-security/2019/05/02/1http://www.openwall.com/lists/oss-security/2019/05/05/4http://www.securityfocus.com/bid/108142https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.0.13https://git.kernel.org/pub/scm/linux/kernel/git/davem/net.git/commit/?id=4dd2b82d5adfbe0b1587ccad7a8f76d826120f37https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z7CYLTCIRTKUB4R2TLLUYPZLDQL44OBG/https://security.netapp.com/advisory/ntap-20190517-0002/https://support.f5.com/csp/article/K69550896https://usn.ubuntu.com/3979-1/https://www.spinics.net/lists/netdev/msg568315.htmlhttp://www.openwall.com/lists/oss-security/2019/05/02/1http://www.openwall.com/lists/oss-security/2019/05/05/4http://www.securityfocus.com/bid/108142https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.0.13https://git.kernel.org/pub/scm/linux/kernel/git/davem/net.git/commit/?id=4dd2b82d5adfbe0b1587ccad7a8f76d826120f37https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z7CYLTCIRTKUB4R2TLLUYPZLDQL44OBG/https://security.netapp.com/advisory/ntap-20190517-0002/https://support.f5.com/csp/article/K69550896https://usn.ubuntu.com/3979-1/https://www.spinics.net/lists/netdev/msg568315.html
2019-05-02
Published