SACK can cause extensive memory use via fragmented resend queue
Published Jun 18, 2019
7.5
HIGHCVSS 3.0
EPSS 94.69%
Description
Jonathan Looney discovered that the TCP retransmission queue implementation in tcp_fragment in the Linux kernel could be fragmented when handling certain TCP Selective Acknowledgment (SACK) sequences. A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11, and is fixed in commit f070ef2ac66716357066b683fb0baf55f8191a2e.
Affected products
-
- Version 4.14StatusaffectedConstraints<4.14.127
- Version 4.19StatusaffectedConstraints<4.19.52
- Version 4.4StatusaffectedConstraints<4.4.182
- Version 4.9StatusaffectedConstraints<4.9.182
- Version 5.1StatusaffectedConstraints<5.1.11
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux kernel | n/a |
|
Configuration 1
- < 4.4.182
- ≥ 4.5 · < 4.9.182
- ≥ 4.10 · < 4.14.127
- ≥ 4.15 · < 4.19.52
- ≥ 4.20 · < 5.1.11
Configuration 2
- ≥ 11.5.2 · ≤ 11.6.4
- ≥ 12.1.0 · ≤ 12.1.4
- ≥ 13.1.0 · ≤ 13.1.1
- ≥ 14.0.0 · ≤ 14.1.0
- 15.0.0
Configuration 3
- ≥ 11.5.2 · ≤ 11.6.4
- ≥ 12.1.0 · ≤ 12.1.4
- ≥ 13.1.0 · ≤ 13.1.1
- ≥ 14.0.0 · ≤ 14.1.0
- 15.0.0
Configuration 4
- ≥ 11.5.2 · ≤ 11.6.4
- ≥ 12.1.0 · ≤ 12.1.4
- ≥ 13.1.0 · ≤ 13.1.1
- ≥ 14.0.0 · ≤ 14.1.0
- 15.0.0
Configuration 5
- ≥ 11.5.2 · ≤ 11.6.4
- ≥ 12.1.0 · ≤ 12.1.4
- ≥ 13.1.0 · ≤ 13.1.1
- ≥ 14.0.0 · ≤ 14.1.0
- 15.0.0
Configuration 6
- ≥ 11.5.2 · ≤ 11.6.4
- ≥ 12.1.0 · ≤ 12.1.4
- ≥ 13.1.0 · ≤ 13.1.1
- ≥ 14.0.0 · ≤ 14.1.0
- 15.0.0
Configuration 7
- ≥ 11.5.2 · ≤ 11.6.4
- ≥ 12.1.0 · ≤ 12.1.4
- ≥ 13.1.0 · ≤ 13.1.1
- ≥ 14.0.0 · ≤ 14.1.0
- 15.0.0
Configuration 8
- ≥ 11.5.2 · ≤ 11.6.4
- ≥ 12.1.0 · ≤ 12.1.4
- ≥ 13.1.0 · ≤ 13.1.1
- ≥ 14.0.0 · ≤ 14.1.0
- 15.0.0
Configuration 9
- ≥ 11.5.2 · ≤ 11.6.4
- ≥ 12.1.0 · ≤ 12.1.4
- ≥ 13.1.0 · ≤ 13.1.1
- ≥ 14.0.0 · ≤ 14.1.0
- 15.0.0
Configuration 10
- ≥ 11.5.2 · ≤ 11.6.4
- ≥ 12.1.0 · ≤ 12.1.4
- ≥ 13.1.0 · ≤ 13.1.1
- ≥ 14.0.0 · ≤ 14.1.0
- 15.0.0
Configuration 11
- ≥ 11.5.2 · ≤ 11.6.4
- ≥ 12.1.0 · ≤ 12.1.4
- ≥ 13.1.0 · ≤ 13.1.1
- ≥ 14.0.0 · ≤ 14.1.0
- 15.0.0
Configuration 12
- ≥ 11.5.2 · ≤ 11.6.4
- ≥ 12.1.0 · ≤ 12.1.4
- ≥ 13.1.0 · ≤ 13.1.1
- ≥ 14.0.0 · ≤ 14.1.0
- 15.0.0
Configuration 13
- ≥ 11.5.2 · ≤ 11.6.4
- ≥ 12.1.0 · ≤ 12.1.4
- ≥ 13.1.0 · ≤ 13.1.1
- ≥ 14.0.0 · ≤ 14.1.0
- 15.0.0
Configuration 14
- ≥ 11.5.2 · ≤ 11.6.4
- ≥ 12.1.0 · ≤ 12.1.4
- ≥ 13.1.0 · ≤ 13.1.1
- ≥ 14.0.0 · ≤ 14.1.0
- 15.0.0
Configuration 15
- 12.04
- 14.04
- 16.04
- 18.04
- 18.10
- 19.04
Configuration 16
- n/a
- 5.0
- 6.0
- 7.0
- 8.0
- 6.5
- 6.6
- 7.4
- 7.5
- 2.0
Configuration 17
- n/a
- n/a
- n/a
Configuration 18
- ≥ 5.0.0 · ≤ 5.1.0
No data.
Red Hat Enterprise Linux 6
kernel-0:2.6.32-754.15.3.el6
Fixed · RHSA-2019:1488
Red Hat Enterprise Linux 6.5 Advanced Update Support
kernel-0:2.6.32-431.95.3.el6
Fixed · RHSA-2019:1490
Red Hat Enterprise Linux 6.6 Advanced Update Support
kernel-0:2.6.32-504.79.3.el6
Fixed · RHSA-2019:1489
Red Hat Enterprise Linux 7
kernel-0:3.10.0-957.21.3.el7
Fixed · RHSA-2019:1481
Red Hat Enterprise Linux 7
kernel-alt-0:4.14.0-115.8.2.el7a
Fixed · RHSA-2019:1602
Red Hat Enterprise Linux 7
kernel-rt-0:3.10.0-957.21.3.rt56.935.el7
Fixed · RHSA-2019:1486
Red Hat Enterprise Linux 7.2 Advanced Update Support
kernel-0:3.10.0-327.79.2.el7
Fixed · RHSA-2019:1485
Red Hat Enterprise Linux 7.2 Telco Extended Update Support
kernel-0:3.10.0-327.79.2.el7
Fixed · RHSA-2019:1485
Red Hat Enterprise Linux 7.2 Update Services for SAP Solutions
kernel-0:3.10.0-327.79.2.el7
Fixed · RHSA-2019:1485
Red Hat Enterprise Linux 7.3 Advanced Update Support
kernel-0:3.10.0-514.66.2.el7
Fixed · RHSA-2019:1484
Red Hat Enterprise Linux 7.3 Telco Extended Update Support
kernel-0:3.10.0-514.66.2.el7
Fixed · RHSA-2019:1484
Red Hat Enterprise Linux 7.3 Update Services for SAP Solutions
kernel-0:3.10.0-514.66.2.el7
Fixed · RHSA-2019:1484
Red Hat Enterprise Linux 7.4 Extended Update Support
kernel-0:3.10.0-693.50.3.el7
Fixed · RHSA-2019:1483
Red Hat Enterprise Linux 7.5 Extended Update Support
kernel-0:3.10.0-862.34.2.el7
Fixed · RHSA-2019:1482
Red Hat Enterprise Linux 8
kernel-0:4.18.0-80.4.2.el8_0
Fixed · RHSA-2019:1479
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-80.4.2.rt9.152.el8_0
Fixed · RHSA-2019:1480
Red Hat Enterprise MRG 2
kernel-rt-1:3.10.0-693.50.3.rt56.644.el6rt
Fixed · RHSA-2019:1487
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7
redhat-release-virtualization-host-0:4.3.4-1.el7ev
Fixed · RHSA-2019:1699
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7
redhat-virtualization-host-0:4.3.4-20190620.3.el7_6
Fixed · RHSA-2019:1699
Red Hat Virtualization 4.2 for Red Hat Enterprise Linux 7.6 EUS
redhat-release-virtualization-host-0:4.2-11.1.el7
Fixed · RHSA-2019:1594
Red Hat Virtualization 4.2 for Red Hat Enterprise Linux 7.6 EUS
redhat-virtualization-host-0:4.2-20190618.0.el7_6
Fixed · RHSA-2019:1594
Red Hat Enterprise Linux 5
kernel
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel-0:2.6.32-754.15.3.el6 | Fixed | RHSA-2019:1488 |
| Red Hat Enterprise Linux 6.5 Advanced Update Support | kernel-0:2.6.32-431.95.3.el6 | Fixed | RHSA-2019:1490 |
| Red Hat Enterprise Linux 6.6 Advanced Update Support | kernel-0:2.6.32-504.79.3.el6 | Fixed | RHSA-2019:1489 |
| Red Hat Enterprise Linux 7 | kernel-0:3.10.0-957.21.3.el7 | Fixed | RHSA-2019:1481 |
| Red Hat Enterprise Linux 7 | kernel-alt-0:4.14.0-115.8.2.el7a | Fixed | RHSA-2019:1602 |
| Red Hat Enterprise Linux 7 | kernel-rt-0:3.10.0-957.21.3.rt56.935.el7 | Fixed | RHSA-2019:1486 |
| Red Hat Enterprise Linux 7.2 Advanced Update Support | kernel-0:3.10.0-327.79.2.el7 | Fixed | RHSA-2019:1485 |
| Red Hat Enterprise Linux 7.2 Telco Extended Update Support | kernel-0:3.10.0-327.79.2.el7 | Fixed | RHSA-2019:1485 |
| Red Hat Enterprise Linux 7.2 Update Services for SAP Solutions | kernel-0:3.10.0-327.79.2.el7 | Fixed | RHSA-2019:1485 |
| Red Hat Enterprise Linux 7.3 Advanced Update Support | kernel-0:3.10.0-514.66.2.el7 | Fixed | RHSA-2019:1484 |
| Red Hat Enterprise Linux 7.3 Telco Extended Update Support | kernel-0:3.10.0-514.66.2.el7 | Fixed | RHSA-2019:1484 |
| Red Hat Enterprise Linux 7.3 Update Services for SAP Solutions | kernel-0:3.10.0-514.66.2.el7 | Fixed | RHSA-2019:1484 |
| Red Hat Enterprise Linux 7.4 Extended Update Support | kernel-0:3.10.0-693.50.3.el7 | Fixed | RHSA-2019:1483 |
| Red Hat Enterprise Linux 7.5 Extended Update Support | kernel-0:3.10.0-862.34.2.el7 | Fixed | RHSA-2019:1482 |
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-80.4.2.el8_0 | Fixed | RHSA-2019:1479 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-80.4.2.rt9.152.el8_0 | Fixed | RHSA-2019:1480 |
| Red Hat Enterprise MRG 2 | kernel-rt-1:3.10.0-693.50.3.rt56.644.el6rt | Fixed | RHSA-2019:1487 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 | redhat-release-virtualization-host-0:4.3.4-1.el7ev | Fixed | RHSA-2019:1699 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 | redhat-virtualization-host-0:4.3.4-20190620.3.el7_6 | Fixed | RHSA-2019:1699 |
| Red Hat Virtualization 4.2 for Red Hat Enterprise Linux 7.6 EUS | redhat-release-virtualization-host-0:4.2-11.1.el7 | Fixed | RHSA-2019:1594 |
| Red Hat Virtualization 4.2 for Red Hat Enterprise Linux 7.6 EUS | redhat-virtualization-host-0:4.2-20190618.0.el7_6 | Fixed | RHSA-2019:1594 |
| Red Hat Enterprise Linux 5 | kernel | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Product Security is aware of this issue. Updates will be released as they become available. For additional information, please refer to the Red Hat Knowledgebase article: https://access.redhat.com/security/vulnerabilities/tcpsack Red Hat Enterprise Linux 5 is now in Maintenance Support 2 Phase of maintenance life cycle. This has been rated as having Moderate security impact and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.
Red Hat mitigation
For mitigation, please refer to the Red Hat Knowledgebase article: https://access.redhat.com/security/vulnerabilities/tcpsack
References (36)
- http://packetstormsecurity.com/files/153346/Kernel-Live-Patch-Security-Notice-LSN-0052-1.html x_refsource_MISCThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/154408/Kernel-Live-Patch-Security-Notice-LSN-0055-1.html x_refsource_MISC
- http://packetstormsecurity.com/files/154951/Kernel-Live-Patch-Security-Notice-LSN-0058-1.html x_refsource_MISC
- http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2020-010.txt x_refsource_CONFIRM
- http://www.openwall.com/lists/oss-security/2019/06/28/2 mailing-listx_refsource_MLIST
- http://www.openwall.com/lists/oss-security/2019/07/06/3 mailing-listx_refsource_MLIST
- http://www.openwall.com/lists/oss-security/2019/07/06/4 mailing-listx_refsource_MLIST
- http://www.openwall.com/lists/oss-security/2019/10/24/1 mailing-listx_refsource_MLIST
- http://www.openwall.com/lists/oss-security/2019/10/29/3 mailing-listx_refsource_MLIST
- http://www.vmware.com/security/advisories/VMSA-2019-0010.html x_refsource_CONFIRM
- https://access.redhat.com/errata/RHSA-2019:1594 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2019:1602 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2019:1699 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2019-11478 Vendor Advisory
- https://access.redhat.com/security/vulnerabilities/tcpsack x_refsource_MISCThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1719128 Issue Tracking
- https://cert-portal.siemens.com/productcert/pdf/ssa-462066.pdf x_refsource_CONFIRM
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-3151 Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/davem/net.git/commit/?id=f070ef2ac66716357066b683fb0baf55f8191a2e x_refsource_MISCMailing ListPatchVendor Advisory
- https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-001.md x_refsource_MISCPatchThird Party Advisory
- https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44193 x_refsource_CONFIRMThird Party Advisory
- https://kc.mcafee.com/corporate/index?page=content&id=SB10287 x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2019-11478
- https://patchwork.ozlabs.org/project/netdev/list/?series=114310
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2019-0007 x_refsource_CONFIRM
- https://seclists.org/bugtraq/2019/Jul/30 mailing-listx_refsource_BUGTRAQ
- https://security.netapp.com/advisory/ntap-20190625-0001/ x_refsource_CONFIRM
- https://support.f5.com/csp/article/K26618426 x_refsource_CONFIRMThird Party Advisory
- https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/SACKPanic x_refsource_MISCMitigationThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-11478
- https://www.kb.cert.org/vuls/id/905115 third-party-advisoryx_refsource_CERT-VN
- https://www.openwall.com/lists/oss-security/2019/06/17/5
- https://www.oracle.com/security-alerts/cpujan2020.html x_refsource_MISC
- https://www.oracle.com/security-alerts/cpuoct2020.html x_refsource_MISC
- https://www.synology.com/security/advisory/Synology_SA_19_28 x_refsource_CONFIRM
- https://www.us-cert.gov/ics/advisories/icsa-19-253-03 x_refsource_MISC
Change history (0)
No recorded changes yet.