CVE-2019-11477

Advisory lineage Upstream: 0 Downstream: 54
Modified
Published: 18 Jun 2019, 23:34
Last modified:17 Sept 2024, 02:21

Vulnerability Summary

Overall Risk (default)
medium
45/100
CVSS Score
7.8 HIGH
v2.0 (nvd)
EPSS Score
69.92% CRITICAL
70% probability -4.63%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

18 Jun 2019, 23:34
Published
Vulnerability first disclosed
17 Sept 2024, 02:21
Last Modified
Vulnerability information updated

Description

Jonathan Looney discovered that the TCP_SKB_CB(skb)->tcp_gso_segs value was subject to an integer overflow in the Linux kernel when handling TCP Selective Acknowledgments (SACKs). A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11, and is fixed in commit 3b4929f65b0d8249f19a50245cd88ed1a2f78cff.

CVSS Metrics

  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  • v3.0HIGHScore: 7.5CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  • v2.0HIGHScore: 7.8AV:N/AC:L/Au:N/C:N/I:N/A:C

EPSS Trends

Current EPSS score: 69.92% Percentile: 99%

Techniques & Countermeasures

  • CWE-190Integer Overflow or Wraparound

    The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

Affected Systems

  • canonicalubuntu_linux

    12.04 | 14.04 | 16.04 | 18.04 | 18.10 | 19.04

  • f5big-ip_access_policy_manager

    ≥ 11.5.2, ≤ 11.6.4 | ≥ 12.1.0, ≤ 12.1.4 | ≥ 13.1.0, ≤ 13.1.1 | ≥ 14.0.0, ≤ 14.1.0 | 15.0.0

  • f5big-ip_advanced_firewall_manager

    ≥ 11.5.2, ≤ 11.6.4 | ≥ 12.1.0, ≤ 12.1.4 | ≥ 13.1.0, ≤ 13.1.1 | ≥ 14.0.0, ≤ 14.1.0 | 15.0.0

  • f5big-ip_analytics

    ≥ 11.5.2, ≤ 11.6.4 | ≥ 12.1.0, ≤ 12.1.4 | ≥ 13.1.0, ≤ 13.1.1 | ≥ 14.0.0, ≤ 14.1.0 | 15.0.0

  • f5big-ip_application_acceleration_manager

    ≥ 11.5.2, ≤ 11.6.4 | ≥ 12.1.0, ≤ 12.1.4 | ≥ 13.1.0, ≤ 13.1.1 | ≥ 14.0.0, ≤ 14.1.0 | 15.0.0

  • f5big-ip_application_security_manager

    ≥ 11.5.2, ≤ 11.6.4 | ≥ 12.1.0, ≤ 12.1.4 | ≥ 13.1.0, ≤ 13.1.1 | ≥ 14.0.0, ≤ 14.1.0 | 15.0.0

  • f5big-ip_domain_name_system

    ≥ 11.5.2, ≤ 11.6.4 | ≥ 12.1.0, ≤ 12.1.4 | ≥ 13.1.0, ≤ 13.1.1 | ≥ 14.0.0, ≤ 14.1.0 | 15.0.0

  • f5big-ip_edge_gateway

    ≥ 11.5.2, ≤ 11.6.4 | ≥ 12.1.0, ≤ 12.1.4 | ≥ 13.1.0, ≤ 13.1.1 | ≥ 14.0.0, ≤ 14.1.0 | 15.0.0

  • f5big-ip_fraud_protection_service

    ≥ 11.5.2, ≤ 11.6.4 | ≥ 12.1.0, ≤ 12.1.4 | ≥ 13.1.0, ≤ 13.1.1 | ≥ 14.0.0, ≤ 14.1.0 | 15.0.0

  • f5big-ip_global_traffic_manager

    ≥ 11.5.2, ≤ 11.6.4 | ≥ 12.1.0, ≤ 12.1.4 | ≥ 13.1.0, ≤ 13.1.1 | ≥ 14.0.0, ≤ 14.1.0 | 15.0.0

  • f5big-ip_link_controller

    ≥ 11.5.2, ≤ 11.6.4 | ≥ 12.1.0, ≤ 12.1.4 | ≥ 13.1.0, ≤ 13.1.1 | ≥ 14.0.0, ≤ 14.1.0 | 15.0.0

  • f5big-ip_local_traffic_manager

    ≥ 11.5.2, ≤ 11.6.4 | ≥ 12.1.0, ≤ 12.1.4 | ≥ 13.1.0, ≤ 13.1.1 | ≥ 14.0.0, ≤ 14.1.0 | 15.0.0

  • f5big-ip_policy_enforcement_manager

    ≥ 11.5.2, ≤ 11.6.4 | ≥ 12.1.0, ≤ 12.1.4 | ≥ 13.1.0, ≤ 13.1.1 | ≥ 14.0.0, ≤ 14.1.0 | 15.0.0

  • f5big-ip_webaccelerator

    ≥ 11.5.2, ≤ 11.6.4 | ≥ 12.1.0, ≤ 12.1.4 | ≥ 13.1.0, ≤ 13.1.1 | ≥ 14.0.0, ≤ 14.1.0 | 15.0.0

  • f5traffix_signaling_delivery_controller

    ≥ 5.0.0, ≤ 5.1.0

  • ivanticonnect_secure

    na

  • linuxlinux_kernel

    ≥ 2.6.29, < 3.16.69 | ≥ 3.17, < 4.4.182 | ≥ 4.5, < 4.9.182 | ≥ 4.10, < 4.14.127 | ≥ 4.15, < 4.19.52 | ≥ 4.20, < 5.1.11 | ≥ 4.4, < 4.4.182 | ≥ 4.9, < 4.9.182 | ≥ 4.14, < 4.14.127 | ≥ 4.19, < 4.19.52 | ≥ 5.1, < 5.1.11

  • pulsesecurepulse_policy_secure

    na

  • pulsesecurepulse_secure_virtual_application_delivery_controller

    na

  • redhatenterprise_linux

    5.0 | 6.0 | 7.0 | 8.0

  • redhatenterprise_linux_atomic_host

    na

  • redhatenterprise_linux_aus

    6.5 | 6.6

  • redhatenterprise_linux_eus

    7.4 | 7.5

  • redhatenterprise_mrg

    2.0

References (29)