kernel: tcp: excessive resource consumption for TCP connections with low MSS allows remote denial of service
Published Jun 18, 2019
7.5
HIGHCVSS 3.1
EPSS 91.66%
Description
Jonathan Looney discovered that the Linux kernel default MSS is hard-coded to 48 bytes. This allows a remote peer to fragment TCP resend queues significantly more than if a larger MSS were enforced. A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11, and is fixed in commits 967c05aee439e6e5d7d805e195b3a20ef5c433d6 and 5f3e2bf008c2221478101ee72f5cb4654b9fc363.
Affected products
-
- Version 4.14StatusaffectedConstraints<4.14.127
- Version 4.19StatusaffectedConstraints<4.19.52
- Version 4.4StatusaffectedConstraints<4.4.182
- Version 4.9StatusaffectedConstraints<4.9.182
- Version 5.1StatusaffectedConstraints<5.1.11
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux kernel | n/a |
|
Configuration 1
- ≥ 4.4 · < 4.4.182
- ≥ 4.9 · < 4.9.182
- ≥ 4.14 · < 4.14.127
- ≥ 4.19 · < 4.19.52
- ≥ 5.1 · < 5.1.11
Configuration 2
- ≥ 11.5.2 · < 11.6.5.1
- ≥ 12.1.0 · < 12.1.5.1
- ≥ 13.1.0 · < 13.1.3.2
- ≥ 14.0.0 · < 14.0.1.1
- ≥ 14.1.2 · < 14.1.2.1
- ≥ 15.0.0 · < 15.0.1.1
Configuration 3
- ≥ 11.5.2 · < 11.6.5.1
- ≥ 12.1.0 · < 12.1.5.1
- ≥ 13.1.0 · < 13.1.3.2
- ≥ 14.0.0 · < 14.0.1.1
- ≥ 14.1.2 · < 14.1.2.1
- ≥ 15.0.0 · < 15.0.1.1
Configuration 4
- ≥ 11.5.2 · < 11.6.5.1
- ≥ 12.1.0 · < 12.1.5.1
- ≥ 13.1.0 · < 13.1.3.2
- ≥ 14.0.0 · < 14.0.1.1
- ≥ 14.1.2 · < 14.1.2.1
- ≥ 15.0.0 · < 15.0.1.1
Configuration 5
- ≥ 11.5.2 · < 11.6.5.1
- ≥ 12.1.0 · < 12.1.5.1
- ≥ 13.1.0 · < 13.1.3.2
- ≥ 14.0.0 · < 14.0.1.1
- ≥ 14.1.2 · < 14.1.2.1
- ≥ 15.0.0 · < 15.0.1.1
Configuration 6
- ≥ 11.5.2 · < 11.6.5.1
- ≥ 12.1.0 · < 12.1.5.1
- ≥ 13.1.0 · < 13.1.3.2
- ≥ 14.0.0 · < 14.0.1.1
- ≥ 14.1.2 · < 14.1.2.1
- ≥ 15.0.0 · < 15.0.1.1
Configuration 7
- ≥ 11.5.2 · < 11.6.5.1
- ≥ 12.1.0 · < 12.1.5.1
- ≥ 13.1.0 · < 13.1.3.2
- ≥ 14.0.0 · < 14.0.1.1
- ≥ 14.1.2 · < 14.1.2.1
- ≥ 15.0.0 · < 15.0.1.1
Configuration 8
- ≥ 11.5.2 · < 11.6.5.1
- ≥ 12.1.0 · < 12.1.5.1
- ≥ 13.1.0 · < 13.1.3.2
- ≥ 14.0.0 · < 14.0.1.1
- ≥ 14.1.2 · < 14.1.2.1
- ≥ 15.0.0 · < 15.0.1.1
Configuration 9
- ≥ 11.5.2 · < 11.6.5.1
- ≥ 12.1.0 · < 12.1.5.1
- ≥ 13.1.0 · < 13.1.3.2
- ≥ 14.0.0 · < 14.0.1.1
- ≥ 14.1.2 · < 14.1.2.1
- ≥ 15.0.0 · < 15.0.1.1
Configuration 10
- ≥ 11.5.2 · < 11.6.5.1
- ≥ 12.1.0 · < 12.1.5.1
- ≥ 13.1.0 · < 13.1.3.2
- ≥ 14.0.0 · < 14.0.1.1
- ≥ 14.1.2 · < 14.1.2.1
- ≥ 15.0.0 · < 15.0.1.1
Configuration 11
- ≥ 11.5.2 · < 11.6.5.1
- ≥ 12.1.0 · < 12.1.5.1
- ≥ 13.1.0 · < 13.1.3.2
- ≥ 14.0.0 · < 14.0.1.1
- ≥ 14.1.2 · < 14.1.2.1
- ≥ 15.0.0 · < 15.0.1.1
Configuration 12
- ≥ 11.5.2 · < 11.6.5.1
- ≥ 12.1.0 · < 12.1.5.1
- ≥ 13.1.0 · < 13.1.3.2
- ≥ 14.0.0 · < 14.0.1.1
- ≥ 14.1.2 · < 14.1.2.1
- ≥ 15.0.0 · < 15.0.1.1
Configuration 13
- ≥ 11.5.2 · < 11.6.5.1
- ≥ 12.1.0 · < 12.1.5.1
- ≥ 13.1.0 · < 13.1.3.2
- ≥ 14.0.0 · < 14.0.1.1
- ≥ 14.1.2 · < 14.1.2.1
- ≥ 15.0.0 · < 15.0.1.1
Configuration 14
- ≥ 11.5.2 · < 11.6.5.1
- ≥ 12.1.0 · < 12.1.5.1
- ≥ 13.1.0 · < 13.1.3.2
- ≥ 14.0.0 · < 14.0.1.1
- ≥ 14.1.2 · < 14.1.2.1
- ≥ 15.0.0 · < 15.0.1.1
Configuration 15
- 14.04
- 16.04
- 18.04
- 18.10
- 19.04
Configuration 16
- 7.0
Configuration 17
- ≥ 5.1.0 · ≤ 5.4.0
- ≥ 6.0.0 · ≤ 6.1.0
- 3.1.1
- 2.3.0
- ≥ 5.0.0 · ≤ 5.1.0
Configuration 18
- 4.0
Running on/with
- 7.0
No data.
Red Hat Enterprise Linux 6
kernel-0:2.6.32-754.15.3.el6
Fixed · RHSA-2019:1488
Red Hat Enterprise Linux 6.5 Advanced Update Support
kernel-0:2.6.32-431.95.3.el6
Fixed · RHSA-2019:1490
Red Hat Enterprise Linux 6.6 Advanced Update Support
kernel-0:2.6.32-504.79.3.el6
Fixed · RHSA-2019:1489
Red Hat Enterprise Linux 7
kernel-0:3.10.0-957.21.3.el7
Fixed · RHSA-2019:1481
Red Hat Enterprise Linux 7
kernel-alt-0:4.14.0-115.8.2.el7a
Fixed · RHSA-2019:1602
Red Hat Enterprise Linux 7
kernel-rt-0:3.10.0-957.21.3.rt56.935.el7
Fixed · RHSA-2019:1486
Red Hat Enterprise Linux 7.2 Advanced Update Support
kernel-0:3.10.0-327.79.2.el7
Fixed · RHSA-2019:1485
Red Hat Enterprise Linux 7.2 Telco Extended Update Support
kernel-0:3.10.0-327.79.2.el7
Fixed · RHSA-2019:1485
Red Hat Enterprise Linux 7.2 Update Services for SAP Solutions
kernel-0:3.10.0-327.79.2.el7
Fixed · RHSA-2019:1485
Red Hat Enterprise Linux 7.3 Advanced Update Support
kernel-0:3.10.0-514.66.2.el7
Fixed · RHSA-2019:1484
Red Hat Enterprise Linux 7.3 Telco Extended Update Support
kernel-0:3.10.0-514.66.2.el7
Fixed · RHSA-2019:1484
Red Hat Enterprise Linux 7.3 Update Services for SAP Solutions
kernel-0:3.10.0-514.66.2.el7
Fixed · RHSA-2019:1484
Red Hat Enterprise Linux 7.4 Extended Update Support
kernel-0:3.10.0-693.50.3.el7
Fixed · RHSA-2019:1483
Red Hat Enterprise Linux 7.5 Extended Update Support
kernel-0:3.10.0-862.34.2.el7
Fixed · RHSA-2019:1482
Red Hat Enterprise Linux 8
kernel-0:4.18.0-80.4.2.el8_0
Fixed · RHSA-2019:1479
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-80.4.2.rt9.152.el8_0
Fixed · RHSA-2019:1480
Red Hat Enterprise MRG 2
kernel-rt-1:3.10.0-693.50.3.rt56.644.el6rt
Fixed · RHSA-2019:1487
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7
redhat-release-virtualization-host-0:4.3.4-1.el7ev
Fixed · RHSA-2019:1699
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7
redhat-virtualization-host-0:4.3.4-20190620.3.el7_6
Fixed · RHSA-2019:1699
Red Hat Virtualization 4.2 for Red Hat Enterprise Linux 7.6 EUS
redhat-release-virtualization-host-0:4.2-11.1.el7
Fixed · RHSA-2019:1594
Red Hat Virtualization 4.2 for Red Hat Enterprise Linux 7.6 EUS
redhat-virtualization-host-0:4.2-20190618.0.el7_6
Fixed · RHSA-2019:1594
Red Hat Enterprise Linux 5
kernel
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel-0:2.6.32-754.15.3.el6 | Fixed | RHSA-2019:1488 |
| Red Hat Enterprise Linux 6.5 Advanced Update Support | kernel-0:2.6.32-431.95.3.el6 | Fixed | RHSA-2019:1490 |
| Red Hat Enterprise Linux 6.6 Advanced Update Support | kernel-0:2.6.32-504.79.3.el6 | Fixed | RHSA-2019:1489 |
| Red Hat Enterprise Linux 7 | kernel-0:3.10.0-957.21.3.el7 | Fixed | RHSA-2019:1481 |
| Red Hat Enterprise Linux 7 | kernel-alt-0:4.14.0-115.8.2.el7a | Fixed | RHSA-2019:1602 |
| Red Hat Enterprise Linux 7 | kernel-rt-0:3.10.0-957.21.3.rt56.935.el7 | Fixed | RHSA-2019:1486 |
| Red Hat Enterprise Linux 7.2 Advanced Update Support | kernel-0:3.10.0-327.79.2.el7 | Fixed | RHSA-2019:1485 |
| Red Hat Enterprise Linux 7.2 Telco Extended Update Support | kernel-0:3.10.0-327.79.2.el7 | Fixed | RHSA-2019:1485 |
| Red Hat Enterprise Linux 7.2 Update Services for SAP Solutions | kernel-0:3.10.0-327.79.2.el7 | Fixed | RHSA-2019:1485 |
| Red Hat Enterprise Linux 7.3 Advanced Update Support | kernel-0:3.10.0-514.66.2.el7 | Fixed | RHSA-2019:1484 |
| Red Hat Enterprise Linux 7.3 Telco Extended Update Support | kernel-0:3.10.0-514.66.2.el7 | Fixed | RHSA-2019:1484 |
| Red Hat Enterprise Linux 7.3 Update Services for SAP Solutions | kernel-0:3.10.0-514.66.2.el7 | Fixed | RHSA-2019:1484 |
| Red Hat Enterprise Linux 7.4 Extended Update Support | kernel-0:3.10.0-693.50.3.el7 | Fixed | RHSA-2019:1483 |
| Red Hat Enterprise Linux 7.5 Extended Update Support | kernel-0:3.10.0-862.34.2.el7 | Fixed | RHSA-2019:1482 |
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-80.4.2.el8_0 | Fixed | RHSA-2019:1479 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-80.4.2.rt9.152.el8_0 | Fixed | RHSA-2019:1480 |
| Red Hat Enterprise MRG 2 | kernel-rt-1:3.10.0-693.50.3.rt56.644.el6rt | Fixed | RHSA-2019:1487 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 | redhat-release-virtualization-host-0:4.3.4-1.el7ev | Fixed | RHSA-2019:1699 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 | redhat-virtualization-host-0:4.3.4-20190620.3.el7_6 | Fixed | RHSA-2019:1699 |
| Red Hat Virtualization 4.2 for Red Hat Enterprise Linux 7.6 EUS | redhat-release-virtualization-host-0:4.2-11.1.el7 | Fixed | RHSA-2019:1594 |
| Red Hat Virtualization 4.2 for Red Hat Enterprise Linux 7.6 EUS | redhat-virtualization-host-0:4.2-20190618.0.el7_6 | Fixed | RHSA-2019:1594 |
| Red Hat Enterprise Linux 5 | kernel | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Product Security is aware of this issue. Updates will be released as they become available. For additional information, please refer to the Red Hat Knowledgebase article: https://access.redhat.com/security/vulnerabilities/tcpsack Red Hat Enterprise Linux 5 is now in the Extended Life Phase of maintenance life cycle. This has been rated as having Moderate security impact and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.
Red Hat mitigation
For mitigation, please refer to the Red Hat Knowledgebase article: https://access.redhat.com/security/vulnerabilities/tcpsack
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
AV:N/AC:L/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (29 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 91.66% (0.91660) | 99.81th | v5 (v2026.06.15) |
| Jun 15, 2026 | 91.66% (0.91660) | 99.80th | v5 (v2026.06.15) |
| Nov 21, 2025 | 13.58% (0.13578) | 93.95th | v4 (v2025.03.14) |
| Nov 18, 2025 | 82.88% (0.82875) | 99.33th | v4 (v2025.03.14) |
| Oct 20, 2025 | 14.29% (0.14289) | 94.08th | v4 (v2025.03.14) |
| Oct 17, 2025 | 11.41% (0.11409) | 93.24th | v4 (v2025.03.14) |
| Jul 30, 2025 | 13.51% (0.13508) | 93.93th | v4 (v2025.03.14) |
| Jun 16, 2025 | 12.34% (0.12335) | 93.52th | v4 (v2025.03.14) |
| Jun 15, 2025 | 9.79% (0.09793) | 92.55th | v4 (v2025.03.14) |
| Mar 30, 2025 | 13.01% (0.13006) | 93.45th | v4 (v2025.03.14) |
| Mar 29, 2025 | 52.97% (0.52973) | 97.03th | v4 (v2025.03.14) |
| Mar 17, 2025 | 13.01% (0.13006) | 93.53th | v4 (v2025.03.14) |
| Dec 12, 2024 | 97.38% (0.97376) | 99.93th | v3 (v2023.03.01) |
| Jun 10, 2024 | 97.39% (0.97393) | 99.92th | v3 (v2023.03.01) |
| May 26, 2024 | 97.35% (0.97348) | 99.89th | v3 (v2023.03.01) |
| Feb 12, 2024 | 97.38% (0.97383) | 99.90th | v3 (v2023.03.01) |
| Jan 12, 2024 | 97.42% (0.97425) | 99.93th | v3 (v2023.03.01) |
| Dec 15, 2023 | 97.43% (0.97432) | 99.93th | v3 (v2023.03.01) |
| Sep 27, 2023 | 97.42% (0.97423) | 99.91th | v3 (v2023.03.01) |
| May 9, 2023 | 97.43% (0.97434) | 99.89th | v3 (v2023.03.01) |
| Apr 22, 2023 | 97.44% (0.97440) | 99.89th | v3 (v2023.03.01) |
| Mar 7, 2023 | 97.41% (0.97405) | 99.84th | v3 (v2023.03.01) |
| Mar 6, 2023 | 7.55% (0.07550) | 92.83th | v2 (v2022.01.01) |
| Apr 1, 2022 | 7.55% (0.07550) | 92.13th | v2 (v2022.01.01) |
| Feb 4, 2022 | 60.81% (0.60808) | 98.64th | v2 (v2022.01.01) |
| Feb 3, 2022 | 30.30% (0.30299) | 96.75th | v1 |
| Jan 6, 2022 | 30.30% (0.30299) | 96.71th | v1 |
| Sep 1, 2021 | 8.83% (0.08833) | 93.71th | v1 |
| Apr 14, 2021 | 8.83% (0.08833) | 0.00th | v1 |
References (34)
- http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2020-010.txt x_refsource_CONFIRMThird Party Advisory
- http://www.openwall.com/lists/oss-security/2019/06/28/2 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2019/07/06/3 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2019/07/06/4 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- http://www.securityfocus.com/bid/108818 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2019:1594 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1602 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1699 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-11479 Vendor Advisory
- https://access.redhat.com/security/vulnerabilities/tcpsack x_refsource_MISCThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1719129 Issue Tracking
- https://cert-portal.siemens.com/productcert/pdf/ssa-462066.pdf x_refsource_CONFIRMThird Party Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/davem/net.git/commit/?id=5f3e2bf008c2221478101ee72f5cb4654b9fc363 x_refsource_MISCMailing ListPatchVendor Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/davem/net.git/commit/?id=967c05aee439e6e5d7d805e195b3a20ef5c433d6 x_refsource_MISCMailing ListPatchVendor Advisory
- https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-001.md x_refsource_MISCPatchThird Party Advisory
- https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44193 x_refsource_CONFIRMThird Party Advisory
- https://kc.mcafee.com/corporate/index?page=content&id=SB10287 x_refsource_CONFIRMThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-11479
- https://patchwork.ozlabs.org/project/netdev/list/?series=114310
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2019-0008 x_refsource_CONFIRMThird Party Advisory
- https://security.netapp.com/advisory/ntap-20190625-0001/ x_refsource_CONFIRMThird Party Advisory
- https://support.f5.com/csp/article/K35421172 x_refsource_CONFIRMThird Party Advisory
- https://support.f5.com/csp/article/K35421172?utm_source=f5support&%3Butm_medium=RSS x_refsource_CONFIRM
- https://usn.ubuntu.com/4041-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/4041-2/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/SACKPanic x_refsource_MISCMitigationThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-11479
- https://www.kb.cert.org/vuls/id/905115 third-party-advisoryx_refsource_CERT-VNThird Party AdvisoryUS Government Resource
- https://www.openwall.com/lists/oss-security/2019/06/17/5
- https://www.oracle.com/security-alerts/cpujan2020.html x_refsource_MISCThird Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2020.html x_refsource_MISC
- https://www.synology.com/security/advisory/Synology_SA_19_28 x_refsource_CONFIRMThird Party Advisory
- https://www.us-cert.gov/ics/advisories/icsa-19-253-03 x_refsource_MISCThird Party AdvisoryUS Government Resource
- https://www.us-cert.gov/ics/advisories/icsma-20-170-06 x_refsource_MISCThird Party AdvisoryUS Government Resource
Change history (0)
No recorded changes yet.