Integer overflow in TCP_SKB_CB(skb)->tcp_gso_segs
Published Jun 18, 2019
7.5
HIGHCVSS 3.1
EPSS 98.75%
Description
Jonathan Looney discovered that the TCP_SKB_CB(skb)->tcp_gso_segs value was subject to an integer overflow in the Linux kernel when handling TCP Selective Acknowledgments (SACKs). A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11, and is fixed in commit 3b4929f65b0d8249f19a50245cd88ed1a2f78cff.
Affected products
-
- Version 4.14StatusaffectedConstraints<4.14.127
- Version 4.19StatusaffectedConstraints<4.19.52
- Version 4.4StatusaffectedConstraints<4.4.182
- Version 4.9StatusaffectedConstraints<4.9.182
- Version 5.1StatusaffectedConstraints<5.1.11
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux kernel | n/a |
|
Configuration 1
- ≥ 2.6.29 · < 3.16.69
- ≥ 3.17 · < 4.4.182
- ≥ 4.5 · < 4.9.182
- ≥ 4.10 · < 4.14.127
- ≥ 4.15 · < 4.19.52
- ≥ 4.20 · < 5.1.11
Configuration 2
- ≥ 11.5.2 · ≤ 11.6.4
- ≥ 12.1.0 · ≤ 12.1.4
- ≥ 13.1.0 · ≤ 13.1.1
- ≥ 14.0.0 · ≤ 14.1.0
- 15.0.0
Configuration 3
- ≥ 11.5.2 · ≤ 11.6.4
- ≥ 12.1.0 · ≤ 12.1.4
- ≥ 13.1.0 · ≤ 13.1.1
- ≥ 14.0.0 · ≤ 14.1.0
- 15.0.0
Configuration 4
- ≥ 11.5.2 · ≤ 11.6.4
- ≥ 12.1.0 · ≤ 12.1.4
- ≥ 13.1.0 · ≤ 13.1.1
- ≥ 14.0.0 · ≤ 14.1.0
- 15.0.0
Configuration 5
- ≥ 11.5.2 · ≤ 11.6.4
- ≥ 12.1.0 · ≤ 12.1.4
- ≥ 13.1.0 · ≤ 13.1.1
- ≥ 14.0.0 · ≤ 14.1.0
- 15.0.0
Configuration 6
- ≥ 11.5.2 · ≤ 11.6.4
- ≥ 12.1.0 · ≤ 12.1.4
- ≥ 13.1.0 · ≤ 13.1.1
- ≥ 14.0.0 · ≤ 14.1.0
- 15.0.0
Configuration 7
- ≥ 11.5.2 · ≤ 11.6.4
- ≥ 12.1.0 · ≤ 12.1.4
- ≥ 13.1.0 · ≤ 13.1.1
- ≥ 14.0.0 · ≤ 14.1.0
- 15.0.0
Configuration 8
- ≥ 11.5.2 · ≤ 11.6.4
- ≥ 12.1.0 · ≤ 12.1.4
- ≥ 13.1.0 · ≤ 13.1.1
- ≥ 14.0.0 · ≤ 14.1.0
- 15.0.0
Configuration 9
- ≥ 11.5.2 · ≤ 11.6.4
- ≥ 12.1.0 · ≤ 12.1.4
- ≥ 13.1.0 · ≤ 13.1.1
- ≥ 14.0.0 · ≤ 14.1.0
- 15.0.0
Configuration 10
- ≥ 11.5.2 · ≤ 11.6.4
- ≥ 12.1.0 · ≤ 12.1.4
- ≥ 13.1.0 · ≤ 13.1.1
- ≥ 14.0.0 · ≤ 14.1.0
- 15.0.0
Configuration 11
- ≥ 11.5.2 · ≤ 11.6.4
- ≥ 12.1.0 · ≤ 12.1.4
- ≥ 13.1.0 · ≤ 13.1.1
- ≥ 14.0.0 · ≤ 14.1.0
- 15.0.0
Configuration 12
- ≥ 11.5.2 · ≤ 11.6.4
- ≥ 12.1.0 · ≤ 12.1.4
- ≥ 13.1.0 · ≤ 13.1.1
- ≥ 14.0.0 · ≤ 14.1.0
- 15.0.0
Configuration 13
- ≥ 11.5.2 · ≤ 11.6.4
- ≥ 12.1.0 · ≤ 12.1.4
- ≥ 13.1.0 · ≤ 13.1.1
- ≥ 14.0.0 · ≤ 14.1.0
- 15.0.0
Configuration 14
- ≥ 11.5.2 · ≤ 11.6.4
- ≥ 12.1.0 · ≤ 12.1.4
- ≥ 13.1.0 · ≤ 13.1.1
- ≥ 14.0.0 · ≤ 14.1.0
- 15.0.0
Configuration 15
- 12.04
- 14.04
- 16.04
- 18.04
- 18.10
- 19.04
Configuration 16
- n/a
- 5.0
- 6.0
- 7.0
- 8.0
- 6.5
- 6.6
- 7.4
- 7.5
- 2.0
Configuration 17
- n/a
- n/a
- n/a
Configuration 18
- ≥ 5.0.0 · ≤ 5.1.0
No data.
Red Hat Enterprise Linux 6
kernel-0:2.6.32-754.15.3.el6
Fixed · RHSA-2019:1488
Red Hat Enterprise Linux 6.5 Advanced Update Support
kernel-0:2.6.32-431.95.3.el6
Fixed · RHSA-2019:1490
Red Hat Enterprise Linux 6.6 Advanced Update Support
kernel-0:2.6.32-504.79.3.el6
Fixed · RHSA-2019:1489
Red Hat Enterprise Linux 7
kernel-0:3.10.0-957.21.3.el7
Fixed · RHSA-2019:1481
Red Hat Enterprise Linux 7
kernel-alt-0:4.14.0-115.8.2.el7a
Fixed · RHSA-2019:1602
Red Hat Enterprise Linux 7
kernel-rt-0:3.10.0-957.21.3.rt56.935.el7
Fixed · RHSA-2019:1486
Red Hat Enterprise Linux 7.2 Advanced Update Support
kernel-0:3.10.0-327.79.2.el7
Fixed · RHSA-2019:1485
Red Hat Enterprise Linux 7.2 Telco Extended Update Support
kernel-0:3.10.0-327.79.2.el7
Fixed · RHSA-2019:1485
Red Hat Enterprise Linux 7.2 Update Services for SAP Solutions
kernel-0:3.10.0-327.79.2.el7
Fixed · RHSA-2019:1485
Red Hat Enterprise Linux 7.3 Advanced Update Support
kernel-0:3.10.0-514.66.2.el7
Fixed · RHSA-2019:1484
Red Hat Enterprise Linux 7.3 Telco Extended Update Support
kernel-0:3.10.0-514.66.2.el7
Fixed · RHSA-2019:1484
Red Hat Enterprise Linux 7.3 Update Services for SAP Solutions
kernel-0:3.10.0-514.66.2.el7
Fixed · RHSA-2019:1484
Red Hat Enterprise Linux 7.4 Extended Update Support
kernel-0:3.10.0-693.50.3.el7
Fixed · RHSA-2019:1483
Red Hat Enterprise Linux 7.5 Extended Update Support
kernel-0:3.10.0-862.34.2.el7
Fixed · RHSA-2019:1482
Red Hat Enterprise Linux 8
kernel-0:4.18.0-80.4.2.el8_0
Fixed · RHSA-2019:1479
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-80.4.2.rt9.152.el8_0
Fixed · RHSA-2019:1480
Red Hat Enterprise MRG 2
kernel-rt-1:3.10.0-693.50.3.rt56.644.el6rt
Fixed · RHSA-2019:1487
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7
redhat-release-virtualization-host-0:4.3.4-1.el7ev
Fixed · RHSA-2019:1699
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7
redhat-virtualization-host-0:4.3.4-20190620.3.el7_6
Fixed · RHSA-2019:1699
Red Hat Virtualization 4.2 for Red Hat Enterprise Linux 7.6 EUS
redhat-release-virtualization-host-0:4.2-11.1.el7
Fixed · RHSA-2019:1594
Red Hat Virtualization 4.2 for Red Hat Enterprise Linux 7.6 EUS
redhat-virtualization-host-0:4.2-20190618.0.el7_6
Fixed · RHSA-2019:1594
Red Hat Enterprise Linux 5
kernel
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel-0:2.6.32-754.15.3.el6 | Fixed | RHSA-2019:1488 |
| Red Hat Enterprise Linux 6.5 Advanced Update Support | kernel-0:2.6.32-431.95.3.el6 | Fixed | RHSA-2019:1490 |
| Red Hat Enterprise Linux 6.6 Advanced Update Support | kernel-0:2.6.32-504.79.3.el6 | Fixed | RHSA-2019:1489 |
| Red Hat Enterprise Linux 7 | kernel-0:3.10.0-957.21.3.el7 | Fixed | RHSA-2019:1481 |
| Red Hat Enterprise Linux 7 | kernel-alt-0:4.14.0-115.8.2.el7a | Fixed | RHSA-2019:1602 |
| Red Hat Enterprise Linux 7 | kernel-rt-0:3.10.0-957.21.3.rt56.935.el7 | Fixed | RHSA-2019:1486 |
| Red Hat Enterprise Linux 7.2 Advanced Update Support | kernel-0:3.10.0-327.79.2.el7 | Fixed | RHSA-2019:1485 |
| Red Hat Enterprise Linux 7.2 Telco Extended Update Support | kernel-0:3.10.0-327.79.2.el7 | Fixed | RHSA-2019:1485 |
| Red Hat Enterprise Linux 7.2 Update Services for SAP Solutions | kernel-0:3.10.0-327.79.2.el7 | Fixed | RHSA-2019:1485 |
| Red Hat Enterprise Linux 7.3 Advanced Update Support | kernel-0:3.10.0-514.66.2.el7 | Fixed | RHSA-2019:1484 |
| Red Hat Enterprise Linux 7.3 Telco Extended Update Support | kernel-0:3.10.0-514.66.2.el7 | Fixed | RHSA-2019:1484 |
| Red Hat Enterprise Linux 7.3 Update Services for SAP Solutions | kernel-0:3.10.0-514.66.2.el7 | Fixed | RHSA-2019:1484 |
| Red Hat Enterprise Linux 7.4 Extended Update Support | kernel-0:3.10.0-693.50.3.el7 | Fixed | RHSA-2019:1483 |
| Red Hat Enterprise Linux 7.5 Extended Update Support | kernel-0:3.10.0-862.34.2.el7 | Fixed | RHSA-2019:1482 |
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-80.4.2.el8_0 | Fixed | RHSA-2019:1479 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-80.4.2.rt9.152.el8_0 | Fixed | RHSA-2019:1480 |
| Red Hat Enterprise MRG 2 | kernel-rt-1:3.10.0-693.50.3.rt56.644.el6rt | Fixed | RHSA-2019:1487 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 | redhat-release-virtualization-host-0:4.3.4-1.el7ev | Fixed | RHSA-2019:1699 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 | redhat-virtualization-host-0:4.3.4-20190620.3.el7_6 | Fixed | RHSA-2019:1699 |
| Red Hat Virtualization 4.2 for Red Hat Enterprise Linux 7.6 EUS | redhat-release-virtualization-host-0:4.2-11.1.el7 | Fixed | RHSA-2019:1594 |
| Red Hat Virtualization 4.2 for Red Hat Enterprise Linux 7.6 EUS | redhat-virtualization-host-0:4.2-20190618.0.el7_6 | Fixed | RHSA-2019:1594 |
| Red Hat Enterprise Linux 5 | kernel | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Product Security is aware of this issue. Updates will be released as they become available. For additional information, please refer to the Red Hat Knowledgebase article: https://access.redhat.com/security/vulnerabilities/tcpsack
Red Hat mitigation
For mitigation, please refer to the Red Hat Knowledgebase article: https://access.redhat.com/security/vulnerabilities/tcpsack
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
AV:N/AC:L/Au:N/C:N/I:N/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (36 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 98.75% (0.98745) | 99.92th | v5 (v2026.06.15) |
| Jun 15, 2026 | 98.75% (0.98745) | 99.92th | v5 (v2026.06.15) |
| Jun 8, 2026 | 74.30% (0.74296) | 98.86th | v4 (v2025.03.14) |
| May 5, 2026 | 69.92% (0.69918) | 98.68th | v4 (v2025.03.14) |
| Jan 23, 2026 | 74.55% (0.74552) | 98.81th | v4 (v2025.03.14) |
| Dec 28, 2025 | 70.22% (0.70216) | 98.62th | v4 (v2025.03.14) |
| Dec 27, 2025 | 75.69% (0.75687) | 98.86th | v4 (v2025.03.14) |
| Dec 20, 2025 | 70.22% (0.70216) | 98.61th | v4 (v2025.03.14) |
| Nov 23, 2025 | 74.55% (0.74552) | 98.79th | v4 (v2025.03.14) |
| Nov 21, 2025 | 70.22% (0.70216) | 98.61th | v4 (v2025.03.14) |
| Nov 18, 2025 | 89.84% (0.89845) | 99.66th | v4 (v2025.03.14) |
| Oct 28, 2025 | 71.15% (0.71146) | 98.64th | v4 (v2025.03.14) |
| Oct 27, 2025 | 76.44% (0.76442) | 98.88th | v4 (v2025.03.14) |
| Oct 20, 2025 | 71.15% (0.71146) | 98.64th | v4 (v2025.03.14) |
| Oct 16, 2025 | 75.35% (0.75346) | 98.83th | v4 (v2025.03.14) |
| Oct 1, 2025 | 71.15% (0.71146) | 98.67th | v4 (v2025.03.14) |
| Apr 10, 2025 | 76.44% (0.76442) | 98.88th | v4 (v2025.03.14) |
| Mar 17, 2025 | 80.68% (0.80681) | 99.10th | v4 (v2025.03.14) |
| Dec 12, 2024 | 97.17% (0.97169) | 99.86th | v3 (v2023.03.01) |
| Jun 10, 2024 | 97.18% (0.97179) | 99.82th | v3 (v2023.03.01) |
| May 26, 2024 | 97.16% (0.97162) | 99.81th | v3 (v2023.03.01) |
| Feb 12, 2024 | 97.22% (0.97222) | 99.81th | v3 (v2023.03.01) |
| Jan 12, 2024 | 97.29% (0.97293) | 99.84th | v3 (v2023.03.01) |
| Dec 15, 2023 | 97.30% (0.97305) | 99.85th | v3 (v2023.03.01) |
| Sep 27, 2023 | 97.29% (0.97290) | 99.81th | v3 (v2023.03.01) |
| Aug 13, 2023 | 97.31% (0.97309) | 99.80th | v3 (v2023.03.01) |
| Jul 12, 2023 | 97.27% (0.97265) | 99.76th | v3 (v2023.03.01) |
| May 25, 2023 | 97.24% (0.97243) | 99.73th | v3 (v2023.03.01) |
| May 9, 2023 | 97.31% (0.97309) | 99.77th | v3 (v2023.03.01) |
| Apr 22, 2023 | 97.32% (0.97319) | 99.77th | v3 (v2023.03.01) |
| Mar 7, 2023 | 97.30% (0.97302) | 99.73th | v3 (v2023.03.01) |
| Mar 6, 2023 | 60.81% (0.60808) | 98.92th | v2 (v2022.01.01) |
| Feb 4, 2022 | 60.81% (0.60808) | 98.64th | v2 (v2022.01.01) |
| Feb 3, 2022 | 31.03% (0.31025) | 96.81th | v1 |
| Sep 1, 2021 | 31.03% (0.31025) | 98.57th | v1 |
| Apr 14, 2021 | 31.03% (0.31025) | 0.00th | v1 |
References (35)
- http://packetstormsecurity.com/files/153346/Kernel-Live-Patch-Security-Notice-LSN-0052-1.html x_refsource_MISCThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/154951/Kernel-Live-Patch-Security-Notice-LSN-0058-1.html x_refsource_MISCThird Party AdvisoryVDB Entry
- http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2020-010.txt x_refsource_CONFIRMThird Party Advisory
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20191225-01-kernel-en x_refsource_CONFIRMThird Party Advisory
- http://www.openwall.com/lists/oss-security/2019/06/20/3 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2019/06/28/2 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2019/07/06/3 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2019/07/06/4 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2019/10/24/1 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2019/10/29/3 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- http://www.vmware.com/security/advisories/VMSA-2019-0010.html x_refsource_CONFIRMThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1594 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1602 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1699 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-11477 Vendor Advisory
- https://access.redhat.com/security/vulnerabilities/tcpsack x_refsource_MISCThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1719123 Issue Tracking
- https://cert-portal.siemens.com/productcert/pdf/ssa-462066.pdf x_refsource_CONFIRMThird Party Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/davem/net.git/commit/?id=3b4929f65b0d8249f19a50245cd88ed1a2f78cff x_refsource_MISCMailing ListPatchVendor Advisory
- https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-001.md x_refsource_MISCPatchThird Party Advisory
- https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44193 x_refsource_CONFIRMThird Party Advisory
- https://kc.mcafee.com/corporate/index?page=content&id=SB10287 x_refsource_CONFIRMThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-11477
- https://patchwork.ozlabs.org/project/netdev/list/?series=114310
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2019-0006 x_refsource_CONFIRMThird Party Advisory
- https://security.netapp.com/advisory/ntap-20190625-0001/ x_refsource_CONFIRMThird Party Advisory
- https://support.f5.com/csp/article/K78234183 x_refsource_CONFIRMThird Party Advisory
- https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/SACKPanic x_refsource_MISCMitigationThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-11477
- https://www.kb.cert.org/vuls/id/905115 third-party-advisoryx_refsource_CERT-VNThird Party AdvisoryUS Government Resource
- https://www.openwall.com/lists/oss-security/2019/06/17/5
- https://www.oracle.com/security-alerts/cpujan2020.html x_refsource_MISCThird Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2020.html x_refsource_MISCThird Party Advisory
- https://www.synology.com/security/advisory/Synology_SA_19_28 x_refsource_CONFIRMThird Party Advisory
- https://www.us-cert.gov/ics/advisories/icsa-19-253-03 x_refsource_MISCThird Party AdvisoryUS Government Resource
Change history (0)
No recorded changes yet.