CVE-2019-11477
Jonathan Looney discovered that the TCP_SKB_CB(skb)->tcp_gso_segs value was subject to an integer overflow in the Linux kernel when handling TCP Selective Acknowledgments (SACKs).
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 98.7%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
Jonathan Looney discovered that the TCP_SKB_CB(skb)->tcp_gso_segs value was subject to an integer overflow in the Linux kernel when handling TCP Selective Acknowledgments (SACKs). A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11, and is fixed in commit 3b4929f65b0d8249f19a50245cd88ed1a2f78cff.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 98.75% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-190
- Affected
- linux/linux kernel · f5/big-ip advanced firewall manager · f5/big-ip access policy manager · f5/big-ip application acceleration manager · f5/big-ip link controller · f5/big-ip policy enforcement manager · f5/big-ip webaccelerator · f5/big-ip application security manager · f5/big-ip local traffic manager · f5/big-ip fraud protection service · f5/big-ip global traffic manager · f5/big-ip analytics · f5/big-ip edge gateway · f5/big-ip domain name system · canonical/ubuntu linux · redhat/enterprise linux atomic host · redhat/enterprise linux · redhat/enterprise linux aus · redhat/enterprise linux eus · redhat/enterprise mrg · +4 more
- Source
- security@ubuntu.com
References
- http://packetstormsecurity.com/files/153346/Kernel-Live-Patch-Security-Notice-LSN-0052-1.htmlThird Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/154951/Kernel-Live-Patch-Security-Notice-LSN-0058-1.htmlThird Party Advisory, VDB Entry
- http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2020-010.txtThird Party Advisory
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20191225-01-kernel-enThird Party Advisory
- http://www.openwall.com/lists/oss-security/2019/06/20/3Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2019/06/28/2Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2019/07/06/3Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2019/07/06/4Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2019/10/24/1Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2019/10/29/3Mailing List, Third Party Advisory
- http://www.vmware.com/security/advisories/VMSA-2019-0010.htmlThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1594Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1602Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1699Third Party Advisory
- https://access.redhat.com/security/vulnerabilities/tcpsackThird Party Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-462066.pdfThird Party Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/davem/net.git/commit/?id=3b4929f65b0d8249f19a50245cd88ed1a2f78cffMailing List, Patch, Vendor Advisory
- https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-001.mdPatch, Third Party Advisory
- https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44193Third Party Advisory
- https://kc.mcafee.com/corporate/index?page=content&id=SB10287Third Party Advisory
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2019-0006Third Party Advisory
- https://security.netapp.com/advisory/ntap-20190625-0001/Third Party Advisory
- https://support.f5.com/csp/article/K78234183Third Party Advisory
- https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/SACKPanicMitigation, Third Party Advisory
- https://www.kb.cert.org/vuls/id/905115Third Party Advisory, US Government Resource
- https://www.oracle.com/security-alerts/cpujan2020.htmlThird Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2020.htmlThird Party Advisory
- https://www.synology.com/security/advisory/Synology_SA_19_28Third Party Advisory
- https://www.us-cert.gov/ics/advisories/icsa-19-253-03Third Party Advisory, US Government Resource
- http://packetstormsecurity.com/files/153346/Kernel-Live-Patch-Security-Notice-LSN-0052-1.htmlThird Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.