ISOMAN

CVE

CVE-2019-11478

Jonathan Looney discovered that the TCP retransmission queue implementation in tcp_fragment in the Linux kernel could be fragmented when handling certain TCP Selective Acknowledgment (SACK) sequences. A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11, and is fixed in commit f070ef2ac66716357066b683fb0baf55f8191a2e.

Severity
MEDIUM
CVSS
5.3
Published
Modified

Linked Releases

References

  1. http://packetstormsecurity.com/files/153346/Kernel-Live-Patch-Security-Notice-LSN-0052-1.html
  2. http://packetstormsecurity.com/files/154408/Kernel-Live-Patch-Security-Notice-LSN-0055-1.html
  3. http://packetstormsecurity.com/files/154951/Kernel-Live-Patch-Security-Notice-LSN-0058-1.html
  4. http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2020-010.txt
  5. http://www.openwall.com/lists/oss-security/2019/06/28/2
  6. http://www.openwall.com/lists/oss-security/2019/07/06/3
  7. http://www.openwall.com/lists/oss-security/2019/07/06/4
  8. http://www.openwall.com/lists/oss-security/2019/10/24/1
  9. http://www.openwall.com/lists/oss-security/2019/10/29/3
  10. http://www.vmware.com/security/advisories/VMSA-2019-0010.html
  11. https://access.redhat.com/errata/RHSA-2019:1594
  12. https://access.redhat.com/errata/RHSA-2019:1602
  13. https://access.redhat.com/errata/RHSA-2019:1699
  14. https://access.redhat.com/security/vulnerabilities/tcpsack
  15. https://cert-portal.siemens.com/productcert/pdf/ssa-462066.pdf
  16. https://git.kernel.org/pub/scm/linux/kernel/git/davem/net.git/commit/?id=f070ef2ac66716357066b683fb0baf55f8191a2e
  17. https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-001.md
  18. https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44193
  19. https://kc.mcafee.com/corporate/index?page=content&id=SB10287
  20. https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2019-0007