CVE-2019-11478 vulnerability in F5 Networks and Other Products
Published on June 19, 2019
Jonathan Looney discovered that the TCP retransmission queue implementation in tcp_fragment in the Linux kernel could be fragmented when handling certain TCP Selective Acknowledgment (SACK) sequences. A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11, and is fixed in commit f070ef2ac66716357066b683fb0baf55f8191a2e.
Weakness Type
Allocation of Resources Without Limits or Throttling
The software allocates a reusable resource or group of resources on behalf of an actor without imposing any restrictions on the size or number of resources that can be allocated, in violation of the intended security policy for that actor.
Products Associated with CVE-2019-11478
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2019-11478 are published in these products:
Affected Versions
Linux kernel:- Version 4.4 and below 4.4.182 is affected.
- Version 4.9 and below 4.9.182 is affected.
- Version 4.14 and below 4.14.127 is affected.
- Version 4.19 and below 4.19.52 is affected.
- Version 5.1 and below 5.1.11 is affected.
Exploit Probability
EPSS
30.13%
Percentile
96.55%
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.