Description
An issue was discovered in net/ipv4/sysctl_net_ipv4.c in the Linux kernel before 5.0.11. There is a net/ipv4/tcp_input.c signed integer overflow in tcp_ack_update_rtt() when userspace writes a very large integer to /proc/sys/net/ipv4/tcp_min_rtt_wlen, leading to a denial of service or possibly unspecified other impact, aka CID-19fad20d15a6.
Published: 2019-11-07
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2019-8509 An issue was discovered in net/ipv4/sysctl_net_ipv4.c in the Linux kernel before 5.0.11. There is a net/ipv4/tcp_input.c signed integer overflow in tcp_ack_update_rtt() when userspace writes a very large integer to /proc/sys/net/ipv4/tcp_min_rtt_wlen, leading to a denial of service or possibly unspecified other impact, aka CID-19fad20d15a6.
History

No history.

Subscriptions

Broadcom Fabric Operating System
Linux Linux Kernel
Netapp Active Iq Unified Manager Aff A400 Aff A400 Firmware Aff A700s Aff A700s Firmware Data Availability Services E-series Santricity Os Controller Fas8300 Fas8300 Firmware Fas8700 Fas8700 Firmware H610s H610s Firmware Hci Compute Node Hci Management Node Hci Storage Node Solidfire Steelstore Cloud Integrated Storage
Opensuse Leap
Redhat Enterprise Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T02:02:39.538Z

Reserved: 2019-11-07T00:00:00.000Z

Link: CVE-2019-18805

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-11-07T14:15:11.067

Modified: 2024-11-21T04:33:36.167

Link: CVE-2019-18805

cve-icon Redhat

Severity : Moderate

Publid Date: 2019-04-16T00:00:00Z

Links: CVE-2019-18805 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses