Jonathan Looney discovered that the Linux kernel default MSS is hard-coded to 48 bytes. This allows a remote peer to fragment TCP resend queues significantly more than if a larger MSS were enforced. A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11, and is fixed in commits 967c05aee439e6e5d7d805e195b3a20ef5c433d6 and 5f3e2bf008c2221478101ee72f5cb4654b9fc363.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Canonical
Subscribe
|
Ubuntu Linux
Subscribe
|
|
F5
Subscribe
|
Big-ip Access Policy Manager
Subscribe
Big-ip Advanced Firewall Manager
Subscribe
Big-ip Analytics
Subscribe
Big-ip Application Acceleration Manager
Subscribe
Big-ip Application Security Manager
Subscribe
Big-ip Domain Name System
Subscribe
Big-ip Edge Gateway
Subscribe
Big-ip Fraud Protection Service
Subscribe
Big-ip Global Traffic Manager
Subscribe
Big-ip Link Controller
Subscribe
Big-ip Local Traffic Manager
Subscribe
Big-ip Policy Enforcement Manager
Subscribe
Big-ip Webaccelerator
Subscribe
Big-iq Centralized Management
Subscribe
Enterprise Manager
Subscribe
Iworkflow
Subscribe
Traffix Signaling Delivery Controller
Subscribe
|
|
Linux
Subscribe
|
Linux Kernel
Subscribe
|
|
Redhat
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1823-1 | linux security update |
Debian DLA |
DLA-1824-1 | linux-4.9 security update |
Debian DSA |
DSA-4465-1 | linux security update |
Ubuntu USN |
USN-4041-1 | Linux kernel update |
Ubuntu USN |
USN-4041-2 | Linux kernel (HWE) update |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: canonical
Published:
Updated: 2024-09-16T23:22:00.170Z
Reserved: 2019-04-23T00:00:00
Link: CVE-2019-11479
No data.
Status : Modified
Published: 2019-06-19T00:15:12.767
Modified: 2024-11-21T04:21:09.880
Link: CVE-2019-11479
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
Ubuntu USN