Vulnerability record · CVE-2019-11477 · published 19 June 2019
CVE-2019-11477: Linux kernel TCP SACK integer overflow causes denial of service
Linux · Linux Kernel
The Linux kernel mishandles the TCP_SKB_CB(skb)->tcp_gso_segs value when processing TCP Selective Acknowledgments (SACKs), allowing an integer overflow. A remote attacker can trigger this to crash or hang the kernel, causing a denial of service. The flaw is fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, and 5.1.11.
Description
Jonathan Looney discovered that the TCP_SKB_CB(skb)->tcp_gso_segs value was subject to an integer overflow in the Linux kernel when handling TCP Selective Acknowledgments (SACKs). A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11, and is fixed in commit 3b4929f65b0d8249f19a50245cd88ed1a2f78cff.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityCVSS 7.5 high severity, remote unauthenticated denial of service, and very high EPSS probability despite not being in KEV.
What it is
The Linux kernel mishandles the TCP_SKB_CB(skb)->tcp_gso_segs value when processing TCP Selective Acknowledgments (SACKs), allowing an integer overflow. A remote attacker can trigger this to crash or hang the kernel, causing a denial of service. The flaw is fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, and 5.1.11.
Impact
An attacker gains the ability to cause a denial of service, taking down or degrading the affected system's networking and availability. There is no confidentiality or integrity impact per the CVSS vector.
Attack surface
Reachable over the network via crafted TCP SACK packets; no authentication or user interaction is required (CVSS AV:N/PR:N/UI:N). Any system running an unpatched affected kernel and accepting TCP connections is exposed.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.98745, 99.924th percentile), indicating a high likelihood of exploitation activity. References include patch and vendor advisories but no public exploit tag.
What to do
- Patch to a fixed kernel release (4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11) or later, or apply the upstream commit 3b4929f65b0d8249f19a50245cd88ed1a2f78cff.
- If immediate patching is not possible, disable TCP SACK processing (e.g., sysctl net.ipv4.tcp_sack=0) as a temporary mitigation, understanding it may affect performance.
- Apply vendor-specific updates for affected products (F5 BIG-IP modules, Ubuntu, Red Hat Enterprise Linux, and others listed).
- Restrict or filter inbound TCP traffic where feasible to reduce exposure to untrusted networks.
Detection
- Monitor for kernel panics, oops messages, or unexpected reboots on Linux hosts, especially those exposed to untrusted networks.
- Track TCP SACK-related anomalies or spikes in retransmissions and connection resets using network monitoring.
- Audit kernel versions across the fleet to identify unpatched systems against the fixed releases.
- Review system logs for signs of denial-of-service conditions correlated with network traffic.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
24 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2019-11477 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-11477), CISA KEV, FIRST EPSS (scores of 2026-09-22). This page is refreshed as NVD updates the record.