MGASA-2019-0195

Advisory lineage Upstream: 4 Downstream: 0
Published: 21 Jun 2019, 01:07
Last modified:16 Apr 2026, 04:26

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

21 Jun 2019, 01:07
Published
Vulnerability first disclosed
16 Apr 2026, 04:26
Last Modified
Vulnerability information updated

Description

Updated kernel packages fix security vulnerability This kernel update is based on the upstream 4.14.127 and fixes at least the following security issues: Jonathan Looney discovered that it is possible to send a crafted sequence of SACKs which will fragment the RACK send map. An attacker may be able to further exploit the fragmented send map to cause an expensive linked-list walk for subsequent SACKs received for that same TCP connection (CVE-2019-5599). Jonathan Looney discovered that the TCP_SKB_CB(skb)->tcp_gso_segs value was subject to an integer overflow in the Linux kernel when handling TCP Selective Acknowledgments (SACKs). A remote attacker could use this to cause a denial of service (CVE-2019-11477). Jonathan Looney discovered that the TCP retransmission queue implementation in tcp_fragment in the Linux kernel could be fragmented when handling certain TCP Selective Acknowledgment (SACK) sequences. A remote attacker could use this to cause a denial of service (CVE-2019-11478). Jonathan Looney discovered that the Linux kernel default MSS is hard-coded to 48 bytes. This allows a remote peer to fragment TCP resend queues significantly more than if a larger MSS were enforced. A remote attacker could use this to cause a denial of service (CVE-2019-11479). WireGuard has been updated to 0.0.20190601. For other uptstream fixes in this update, see the referenced changelogs.

Affected Systems

  • mageiakernel

    < 4.14.127-1.mga6

  • mageiakernel-userspace-headers

    < 4.14.127-1.mga6

  • mageiakmod-vboxadditions

    < 6.0.8-4.mga6

  • mageiakmod-virtualbox

    < 6.0.8-4.mga6

  • mageiakmod-xtables-addons

    < 2.13-88.mga6

  • mageiawireguard-tools

    < 0.0.20190601-1.mga6

References (9)