CVE-2019-11479
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
Jonathan Looney discovered that the Linux kernel default MSS is hard-coded to 48 bytes. This allows a remote peer to fragment TCP resend queues significantly more than if a larger MSS were enforced. A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11, and is fixed in commits 967c05aee439e6e5d7d805e195b3a20ef5c433d6 and 5f3e2bf008c2221478101ee72f5cb4654b9fc363.
Affected (94)
Products: Linux: Linux Kernel · F5: Big Ip Advanced Firewall Manager, Big Ip Access Policy Manager, Big Ip Application Acceleration Manager, Big Ip Link Controller, Big Ip Policy Enforcement Manager, Big Ip Webaccelerator, Big Ip Application Security Manager, Big Ip Local Traffic Manager, Big Ip Fraud Protection Service, Big Ip Global Traffic Manager, Big Ip Analytics, Big Ip Edge Gateway, Big Ip Domain Name System, Big Iq Centralized Management, Enterprise Manager, Iworkflow, Traffix Signaling Delivery Controller · Canonical: Ubuntu Linux · +1 more
Show all products
Linux: Linux Kernel · F5: Big Ip Advanced Firewall Manager, Big Ip Access Policy Manager, Big Ip Application Acceleration Manager, Big Ip Link Controller, Big Ip Policy Enforcement Manager, Big Ip Webaccelerator, Big Ip Application Security Manager, Big Ip Local Traffic Manager, Big Ip Fraud Protection Service, Big Ip Global Traffic Manager, Big Ip Analytics, Big Ip Edge Gateway, Big Ip Domain Name System, Big Iq Centralized Management, Enterprise Manager, Iworkflow, Traffix Signaling Delivery Controller · Canonical: Ubuntu Linux · Redhat: Virtualization Host
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 4.14 to 4.14.127 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.2 to 11.6.5.1 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.2 to 11.6.5.1 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.2 to 11.6.5.1 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.2 to 11.6.5.1 |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.2 to 11.6.5.1 |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.2 to 11.6.5.1 |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.2 to 11.6.5.1 |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.2 to 11.6.5.1 |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.2 to 11.6.5.1 |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.2 to 11.6.5.1 |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.2 to 11.6.5.1 |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.2 to 11.6.5.1 |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.2 to 11.6.5.1 |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Version 14.04 |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| From 5.1.0 to 5.4.0 | |
| Version 3.1.1 | |
| Version 2.3.0 | |
| From 5.0.0 to 5.1.0 |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.0 |
| Running on/with | Platform Versions |
|---|---|
Redhat Enterprise Linux | Version 7.0 |
Related CWEs
CWE-405
Asymmetric Resource Consumption (Amplification)
The product does not properly control situations in which an adversary can cause the product to consume or produce excessive resources without requiring the adversary to invest equivalent work or otherwise prove authorization, i.e., the adversary's influence is "asymmetric."
CWE-770
Allocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any restrictions on the size or number of resources that can be allocated, in violation of the intended security policy for that actor.
References (56)
Source: security@ubuntu.com
Third Party Advisory
Source: security@ubuntu.com
Mailing ListThird Party Advisory
Source: security@ubuntu.com
Mailing ListThird Party Advisory
Source: security@ubuntu.com
Mailing ListThird Party Advisory
Source: security@ubuntu.com
Third Party Advisory
Source: security@ubuntu.com
Third Party Advisory
Source: security@ubuntu.com
Mailing ListPatchVendor Advisory
Source: security@ubuntu.com
Mailing ListPatchVendor Advisory
Source: security@ubuntu.com
PatchThird Party Advisory
Source: security@ubuntu.com
Third Party Advisory
Source: security@ubuntu.com
Third Party Advisory
Source: security@ubuntu.com
Third Party Advisory
Source: security@ubuntu.com
Third Party Advisory
Source: security@ubuntu.com
Source: security@ubuntu.com
MitigationThird Party Advisory
Source: security@ubuntu.com
Third Party AdvisoryUS Government Resource
Source: security@ubuntu.com
Third Party Advisory
Source: security@ubuntu.com
Source: security@ubuntu.com
Third Party Advisory
Source: security@ubuntu.com
Third Party AdvisoryUS Government Resource
Source: security@ubuntu.com
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Timeline
No history available yet.