CVE Database
/

CVE-2019-11479

Back to search

CVE-2019-11479

Published: Jun 18, 2019

Modified: Sep 16, 2024

PUBLISHED

CVSS v3.0

5.3

MEDIUM

Description

Jonathan Looney discovered that the Linux kernel default MSS is hard-coded to 48 bytes. This allows a remote peer to fragment TCP resend queues significantly more than if a larger MSS were enforced. A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11, and is fixed in commits 967c05aee439e6e5d7d805e195b3a20ef5c433d6 and 5f3e2bf008c2221478101ee72f5cb4654b9fc363.

VendorProductVersions

Linux

Linux kernel

affected
4.4 - < 4.4.182
affected
4.9 - < 4.9.182
affected
4.14 - < 4.14.127
affected
4.19 - < 4.19.52
affected
5.1 - < 5.1.11

Weaknesses (CWE)

CVSS v3.0 Details

CVSS v3.0 Vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

None

Integrity

None

Availability

Low

References

108818
vdb-entry
x_refsource_BID
VU#905115
third-party-advisory
x_refsource_CERT-VN
RHSA-2019:1594
vendor-advisory
x_refsource_REDHAT
RHSA-2019:1602
vendor-advisory
x_refsource_REDHAT
USN-4041-2
vendor-advisory
x_refsource_UBUNTU
RHSA-2019:1699
vendor-advisory
x_refsource_REDHAT
USN-4041-1
vendor-advisory
x_refsource_UBUNTU

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now