← Vulnerability feed

Vulnerability record · CVE-2019-11479 · published 19 June 2019

CVE-2019-11479: Linux kernel hard-coded 48-byte MSS enables remote TCP denial of service

Linux · Linux Kernel

The Linux kernel hard-codes a default TCP maximum segment size (MSS) of 48 bytes, letting a remote peer force excessive fragmentation of TCP resend queues. This is the SACK Panic family issue and allows a remote attacker to exhaust kernel memory and cause a denial of service. It affects the Linux kernel and multiple downstream products including F5 BIG-IP, Ubuntu, Red Hat Enterprise Linux and others.

7.5 CVSS 3.1 High EPSS 92% · top 0.2% CWE-405 · CWE-405CWE-770 · Allocation without limits
7.5CVSS 3.1 base score, v2 5.0
92%EPSS exploitation probability, 30 days
NoNot in CISA KEV
21Affected product versions listed by NVD
56References
17 Jun 2026Last modified by NVD

Description

Jonathan Looney discovered that the Linux kernel default MSS is hard-coded to 48 bytes. This allows a remote peer to fragment TCP resend queues significantly more than if a larger MSS were enforced. A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11, and is fixed in commits 967c05aee439e6e5d7d805e195b3a20ef5c433d6 and 5f3e2bf008c2221478101ee72f5cb4654b9fc363.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityRemote, unauthenticated, low-complexity availability impact with a very high EPSS score, though not in KEV and requiring no user interaction.

What it is

The Linux kernel hard-codes a default TCP maximum segment size (MSS) of 48 bytes, letting a remote peer force excessive fragmentation of TCP resend queues. This is the SACK Panic family issue and allows a remote attacker to exhaust kernel memory and cause a denial of service. It affects the Linux kernel and multiple downstream products including F5 BIG-IP, Ubuntu, Red Hat Enterprise Linux and others.

Impact

An unauthenticated remote attacker can drive excessive memory allocation in the kernel's TCP resend queues, degrading or halting network service on the target host. No confidentiality or integrity impact is described; the effect is availability loss.

Attack surface

Reachable over the network via TCP traffic to a listening service; the CVSS vector shows AV:N/AC:L/PR:N/UI:N, so no authentication or user interaction is required. Any host running an unpatched affected kernel or downstream product that accepts TCP connections is exposed.

Exploitation

Not listed in CISA KEV and no ransomware usage is documented, but EPSS is very high (0.9166 probability, 99.8th percentile), indicating strong likelihood of attempted exploitation. References are advisories and patches rather than public exploit code.

What to do

  • Patch to a fixed kernel release (4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11) or later, or apply the referenced upstream commits.
  • Apply vendor advisories for F5 BIG-IP, Ubuntu, Red Hat and other listed products, since they ship their own patched builds.
  • Where patching is delayed, apply the documented workarounds such as lowering the advertised MSS or disabling SACK as described in vendor mitigation guidance.
  • Restrict or rate-limit untrusted TCP traffic to exposed services and monitor for abnormal connection patterns.
  • Track kernel and network appliance versions in inventory so unpatched systems are identified quickly.

Detection

  • Monitor for spikes in TCP retransmissions, resend queue growth and kernel memory pressure on exposed hosts.
  • Alert on large volumes of small-MSS TCP connections or unusual SACK behavior from single sources.
  • Watch system logs and monitoring for OOM or network stack stalls correlated with inbound TCP traffic.
  • Use network flow data to flag hosts receiving many fragmented or low-MSS TCP sessions.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

21 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2020-010.txt Third Party Advisory
http://www.openwall.com/lists/oss-security/2019/06/28/2 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2019/07/06/3 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2019/07/06/4 Mailing ListThird Party Advisory
http://www.securityfocus.com/bid/108818 Third Party AdvisoryVDB Entry
https://access.redhat.com/errata/RHSA-2019:1594 Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:1602 Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:1699 Third Party Advisory
https://access.redhat.com/security/vulnerabilities/tcpsack Third Party Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-462066.pdf Third Party Advisory
https://git.kernel.org/pub/scm/linux/kernel/git/davem/net.git/commit/?id=5f3e2bf008c2221478101ee72f5cb4654b9fc363 Mailing ListPatchVendor Advisory
https://git.kernel.org/pub/scm/linux/kernel/git/davem/net.git/commit/?id=967c05aee439e6e5d7d805e195b3a20ef5c433d6 Mailing ListPatchVendor Advisory
https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-001.md PatchThird Party Advisory
https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44193 Third Party Advisory
https://kc.mcafee.com/corporate/index?page=content&id=SB10287 Third Party Advisory
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2019-0008 Third Party Advisory
https://security.netapp.com/advisory/ntap-20190625-0001/ Third Party Advisory
https://support.f5.com/csp/article/K35421172 Third Party Advisory
https://support.f5.com/csp/article/K35421172?utm_source=f5support&amp%3Butm_medium=RSS
https://usn.ubuntu.com/4041-1/ Third Party Advisory
https://usn.ubuntu.com/4041-2/ Third Party Advisory
https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/SACKPanic MitigationThird Party Advisory
https://www.kb.cert.org/vuls/id/905115 Third Party AdvisoryUS Government Resource
https://www.oracle.com/security-alerts/cpujan2020.html Third Party Advisory
https://www.oracle.com/security-alerts/cpuoct2020.html
https://www.synology.com/security/advisory/Synology_SA_19_28 Third Party Advisory
https://www.us-cert.gov/ics/advisories/icsa-19-253-03 Third Party AdvisoryUS Government Resource
https://www.us-cert.gov/ics/advisories/icsma-20-170-06 Third Party AdvisoryUS Government Resource
http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2020-010.txt Third Party Advisory
http://www.openwall.com/lists/oss-security/2019/06/28/2 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2019/07/06/3 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2019/07/06/4 Mailing ListThird Party Advisory
http://www.securityfocus.com/bid/108818 Third Party AdvisoryVDB Entry
https://access.redhat.com/errata/RHSA-2019:1594 Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:1602 Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:1699 Third Party Advisory
https://access.redhat.com/security/vulnerabilities/tcpsack Third Party Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-462066.pdf Third Party Advisory
https://git.kernel.org/pub/scm/linux/kernel/git/davem/net.git/commit/?id=5f3e2bf008c2221478101ee72f5cb4654b9fc363 Mailing ListPatchVendor Advisory
https://git.kernel.org/pub/scm/linux/kernel/git/davem/net.git/commit/?id=967c05aee439e6e5d7d805e195b3a20ef5c433d6 Mailing ListPatchVendor Advisory

Track CVE-2019-11479 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-46747F5 BIG-IP configuration utility authentication bypass allows command executionUndisclosed requests can bypass authentication in the BIG-IP configuration utility, letting a network-positioned attacker execute arbitrary system co…KEVEPSS 97%analysed9.8CVE-2022-1388F5 BIG-IP iControl REST authentication bypassUndisclosed requests to the iControl REST interface on multiple F5 BIG-IP modules can bypass authentication, allowing an unauthenticated remote attac…KEVEPSS 100%analysed9.8CVE-2021-22991F5 BIG-IP TMM URI normalization buffer overflowF5 BIG-IP's Traffic Management Microkernel (TMM) mishandles URI normalization for undisclosed requests to a virtual server, triggering a buffer overf…KEVEPSS 61%analysed9.8CVE-2021-22986F5 BIG-IP iControl REST unauthenticated remote command executionThe iControl REST interface on multiple F5 BIG-IP and BIG-IQ versions exposes an unauthenticated remote command execution flaw, tracked as CWE-918 se…KEVEPSS 100%analysed9.8CVE-2020-5902F5 BIG-IP TMUI path traversal leading to remote code executionThe F5 BIG-IP Traffic Management User Interface (TMUI, also called the Configuration utility) contains a path traversal flaw (CWE-22) in undisclosed …KEVEPSS 100%analysed9.8CVE-2020-11651SaltStack Salt master authentication bypass in ClearFuncsSaltStack Salt before 2019.2.4 and 3000 before 3000.2 fails to properly validate method calls in the salt-master ClearFuncs class, allowing remote un…KEVEPSS 97%analysed9.8CVE-2020-7247OpenSMTPD MAIL FROM command injection allows remote root code executionOpenSMTPD 6.6, as shipped in OpenBSD 6.6 and other products, mishandles input validation in smtp_mailaddr in smtp_session.c, returning an incorrect v…KEVEPSS 99%analysed9.8CVE-2019-11043PHP-FPM buffer overflow enables remote code executionPHP-FPM in certain configurations writes past allocated buffers into FCGI protocol data space, an out-of-bounds write (CWE-787, CWE-120). It affects …KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2019-11479), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.