← Vulnerability feed

Vulnerability record · CVE-2019-11477 · published 19 June 2019

CVE-2019-11477: Linux kernel TCP SACK integer overflow causes denial of service

Linux · Linux Kernel

The Linux kernel mishandles the TCP_SKB_CB(skb)->tcp_gso_segs value when processing TCP Selective Acknowledgments (SACKs), allowing an integer overflow. A remote attacker can trigger this to crash or hang the kernel, causing a denial of service. The flaw is fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, and 5.1.11.

7.5 CVSS 3.1 High EPSS 99% · top 0.1% CWE-190 · Integer overflow
7.5CVSS 3.1 base score, v2 7.8
99%EPSS exploitation probability, 30 days
NoNot in CISA KEV
24Affected product versions listed by NVD
58References
17 Jun 2026Last modified by NVD

Description

Jonathan Looney discovered that the TCP_SKB_CB(skb)->tcp_gso_segs value was subject to an integer overflow in the Linux kernel when handling TCP Selective Acknowledgments (SACKs). A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11, and is fixed in commit 3b4929f65b0d8249f19a50245cd88ed1a2f78cff.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityCVSS 7.5 high severity, remote unauthenticated denial of service, and very high EPSS probability despite not being in KEV.

What it is

The Linux kernel mishandles the TCP_SKB_CB(skb)->tcp_gso_segs value when processing TCP Selective Acknowledgments (SACKs), allowing an integer overflow. A remote attacker can trigger this to crash or hang the kernel, causing a denial of service. The flaw is fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, and 5.1.11.

Impact

An attacker gains the ability to cause a denial of service, taking down or degrading the affected system's networking and availability. There is no confidentiality or integrity impact per the CVSS vector.

Attack surface

Reachable over the network via crafted TCP SACK packets; no authentication or user interaction is required (CVSS AV:N/PR:N/UI:N). Any system running an unpatched affected kernel and accepting TCP connections is exposed.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.98745, 99.924th percentile), indicating a high likelihood of exploitation activity. References include patch and vendor advisories but no public exploit tag.

What to do

  • Patch to a fixed kernel release (4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11) or later, or apply the upstream commit 3b4929f65b0d8249f19a50245cd88ed1a2f78cff.
  • If immediate patching is not possible, disable TCP SACK processing (e.g., sysctl net.ipv4.tcp_sack=0) as a temporary mitigation, understanding it may affect performance.
  • Apply vendor-specific updates for affected products (F5 BIG-IP modules, Ubuntu, Red Hat Enterprise Linux, and others listed).
  • Restrict or filter inbound TCP traffic where feasible to reduce exposure to untrusted networks.

Detection

  • Monitor for kernel panics, oops messages, or unexpected reboots on Linux hosts, especially those exposed to untrusted networks.
  • Track TCP SACK-related anomalies or spikes in retransmissions and connection resets using network monitoring.
  • Audit kernel versions across the fleet to identify unpatched systems against the fixed releases.
  • Review system logs for signs of denial-of-service conditions correlated with network traffic.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

24 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://packetstormsecurity.com/files/153346/Kernel-Live-Patch-Security-Notice-LSN-0052-1.html Third Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/154951/Kernel-Live-Patch-Security-Notice-LSN-0058-1.html Third Party AdvisoryVDB Entry
http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2020-010.txt Third Party Advisory
http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20191225-01-kernel-en Third Party Advisory
http://www.openwall.com/lists/oss-security/2019/06/20/3 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2019/06/28/2 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2019/07/06/3 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2019/07/06/4 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2019/10/24/1 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2019/10/29/3 Mailing ListThird Party Advisory
http://www.vmware.com/security/advisories/VMSA-2019-0010.html Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:1594 Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:1602 Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:1699 Third Party Advisory
https://access.redhat.com/security/vulnerabilities/tcpsack Third Party Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-462066.pdf Third Party Advisory
https://git.kernel.org/pub/scm/linux/kernel/git/davem/net.git/commit/?id=3b4929f65b0d8249f19a50245cd88ed1a2f78cff Mailing ListPatchVendor Advisory
https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-001.md PatchThird Party Advisory
https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44193 Third Party Advisory
https://kc.mcafee.com/corporate/index?page=content&id=SB10287 Third Party Advisory
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2019-0006 Third Party Advisory
https://security.netapp.com/advisory/ntap-20190625-0001/ Third Party Advisory
https://support.f5.com/csp/article/K78234183 Third Party Advisory
https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/SACKPanic MitigationThird Party Advisory
https://www.kb.cert.org/vuls/id/905115 Third Party AdvisoryUS Government Resource
https://www.oracle.com/security-alerts/cpujan2020.html Third Party Advisory
https://www.oracle.com/security-alerts/cpuoct2020.html Third Party Advisory
https://www.synology.com/security/advisory/Synology_SA_19_28 Third Party Advisory
https://www.us-cert.gov/ics/advisories/icsa-19-253-03 Third Party AdvisoryUS Government Resource
http://packetstormsecurity.com/files/153346/Kernel-Live-Patch-Security-Notice-LSN-0052-1.html Third Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/154951/Kernel-Live-Patch-Security-Notice-LSN-0058-1.html Third Party AdvisoryVDB Entry
http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2020-010.txt Third Party Advisory
http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20191225-01-kernel-en Third Party Advisory
http://www.openwall.com/lists/oss-security/2019/06/20/3 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2019/06/28/2 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2019/07/06/3 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2019/07/06/4 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2019/10/24/1 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2019/10/29/3 Mailing ListThird Party Advisory
http://www.vmware.com/security/advisories/VMSA-2019-0010.html Third Party Advisory

Track CVE-2019-11477 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-46747F5 BIG-IP configuration utility authentication bypass allows command executionUndisclosed requests can bypass authentication in the BIG-IP configuration utility, letting a network-positioned attacker execute arbitrary system co…KEVEPSS 97%analysed9.8CVE-2022-1388F5 BIG-IP iControl REST authentication bypassUndisclosed requests to the iControl REST interface on multiple F5 BIG-IP modules can bypass authentication, allowing an unauthenticated remote attac…KEVEPSS 100%analysed9.8CVE-2021-22991F5 BIG-IP TMM URI normalization buffer overflowF5 BIG-IP's Traffic Management Microkernel (TMM) mishandles URI normalization for undisclosed requests to a virtual server, triggering a buffer overf…KEVEPSS 61%analysed9.8CVE-2021-22986F5 BIG-IP iControl REST unauthenticated remote command executionThe iControl REST interface on multiple F5 BIG-IP and BIG-IQ versions exposes an unauthenticated remote command execution flaw, tracked as CWE-918 se…KEVEPSS 100%analysed9.8CVE-2020-5902F5 BIG-IP TMUI path traversal leading to remote code executionThe F5 BIG-IP Traffic Management User Interface (TMUI, also called the Configuration utility) contains a path traversal flaw (CWE-22) in undisclosed …KEVEPSS 100%analysed9.8CVE-2020-11651SaltStack Salt master authentication bypass in ClearFuncsSaltStack Salt before 2019.2.4 and 3000 before 3000.2 fails to properly validate method calls in the salt-master ClearFuncs class, allowing remote un…KEVEPSS 97%analysed9.8CVE-2020-7247OpenSMTPD MAIL FROM command injection allows remote root code executionOpenSMTPD 6.6, as shipped in OpenBSD 6.6 and other products, mishandles input validation in smtp_mailaddr in smtp_session.c, returning an incorrect v…KEVEPSS 99%analysed9.8CVE-2019-11043PHP-FPM buffer overflow enables remote code executionPHP-FPM in certain configurations writes past allocated buffers into FCGI protocol data space, an out-of-bounds write (CWE-787, CWE-120). It affects …KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2019-11477), CISA KEV, FIRST EPSS (scores of 2026-09-22). This page is refreshed as NVD updates the record.