Lucene search

K
redhatcveRedhat.comRH:CVE-2019-11477
HistoryNov 01, 2020 - 9:54 p.m.

CVE-2019-11477

2020-11-0121:54:35
redhat.com
access.redhat.com
44

0.972 High

EPSS

Percentile

99.8%

An integer overflow flaw was found in the way the Linux kernel’s networking subsystem processed TCP Selective Acknowledgment (SACK) segments. While processing SACK segments, the Linux kernel’s socket buffer (SKB) data structure becomes fragmented. Each fragment is about TCP maximum segment size (MSS) bytes. To efficiently process SACK blocks, the Linux kernel merges multiple fragmented SKBs into one, potentially overflowing the variable holding the number of segments. A remote attacker could use this flaw to crash the Linux kernel by sending a crafted sequence of SACK segments on a TCP connection with small value of TCP MSS, resulting in a denial of service (DoS).

Mitigation

For mitigation, please refer to the Red Hat Knowledgebase article: <https://access.redhat.com/security/vulnerabilities/tcpsack&gt;