Vulnerability record · CVE-2019-11478 · published 19 June 2019
CVE-2019-11478: Linux kernel TCP SACK fragmentation denial of service
Linux · Linux Kernel
The TCP retransmission queue implementation in tcp_fragment in the Linux kernel can be fragmented when handling certain TCP Selective Acknowledgment (SACK) sequences, leading to excessive resource consumption. A remote attacker can trigger this to cause a denial of service. The flaw is fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11 and commit f070ef2ac66716357066b683fb0baf55f8191a2e.
Description
Jonathan Looney discovered that the TCP retransmission queue implementation in tcp_fragment in the Linux kernel could be fragmented when handling certain TCP Selective Acknowledgment (SACK) sequences. A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11, and is fixed in commit f070ef2ac66716357066b683fb0baf55f8191a2e.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityRemote, unauthenticated, low-complexity availability impact with very high EPSS, though not in KEV and no confirmed public exploit.
What it is
The TCP retransmission queue implementation in tcp_fragment in the Linux kernel can be fragmented when handling certain TCP Selective Acknowledgment (SACK) sequences, leading to excessive resource consumption. A remote attacker can trigger this to cause a denial of service. The flaw is fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11 and commit f070ef2ac66716357066b683fb0baf55f8191a2e.
Impact
An attacker can exhaust kernel memory and CPU on the target, degrading or halting TCP service for legitimate users. No confidentiality or integrity impact is described; the effect is availability loss.
Attack surface
Reachable over the network via crafted TCP SACK sequences; the CVSS vector shows AV:N/AC:L/PR:N/UI:N, so no authentication or user interaction is required. Any host exposing TCP services with a vulnerable kernel is in scope.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.94686, 99.853rd percentile), indicating elevated likelihood of exploitation activity. References include patch and vendor advisory tags but no public exploit tag.
What to do
- Patch to a fixed kernel release (4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11 or later) or apply commit f070ef2ac66716357066b683fb0baf55f8191a2e.
- Apply vendor advisories for affected products (F5 BIG-IP, Red Hat, Ubuntu, Pulse Secure, and others listed).
- Where patching is delayed, consider disabling or rate-limiting SACK handling per vendor mitigation guidance.
- Monitor and cap TCP retransmission queue memory usage to limit resource exhaustion.
- Inventory internet-facing TCP services and prioritize those on unpatched kernels.
Detection
- Monitor for abnormal TCP retransmission queue growth and kernel memory pressure on exposed hosts.
- Alert on spikes in SACK-related TCP traffic or repeated connection stalls from single sources.
- Track kernel versions against the fixed releases and flag unpatched systems.
- Correlate host availability degradation with TCP SACK packet patterns in network telemetry.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
24 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2019-11478 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-11478), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.