An issue was discovered in net/ipv4/sysctl_net_ipv4.c in the Linux kernel before 5.0.11. There is a net/ipv4/tcp_input.c signed integer overflow in tcp_ack_update_rtt() when userspace writes a very large integer to /proc/sys/net/ipv4/tcp_min_rtt_wlen, leading to a denial of service or possibly unspecified other impact, aka CID-19fad20d15a6.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Broadcom
Subscribe
|
Fabric Operating System
Subscribe
|
|
Linux
Subscribe
|
Linux Kernel
Subscribe
|
|
Netapp
Subscribe
|
Active Iq Unified Manager
Subscribe
Aff A400
Subscribe
Aff A400 Firmware
Subscribe
Aff A700s
Subscribe
Aff A700s Firmware
Subscribe
Data Availability Services
Subscribe
E-series Santricity Os Controller
Subscribe
Fas8300
Subscribe
Fas8300 Firmware
Subscribe
Fas8700
Subscribe
Fas8700 Firmware
Subscribe
H610s
Subscribe
H610s Firmware
Subscribe
Hci Compute Node
Subscribe
Hci Management Node
Subscribe
Hci Storage Node
Subscribe
Solidfire
Subscribe
Steelstore Cloud Integrated Storage
Subscribe
|
|
Opensuse
Subscribe
|
Leap
Subscribe
|
|
Redhat
Subscribe
|
Enterprise Linux
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-8509 | An issue was discovered in net/ipv4/sysctl_net_ipv4.c in the Linux kernel before 5.0.11. There is a net/ipv4/tcp_input.c signed integer overflow in tcp_ack_update_rtt() when userspace writes a very large integer to /proc/sys/net/ipv4/tcp_min_rtt_wlen, leading to a denial of service or possibly unspecified other impact, aka CID-19fad20d15a6. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T02:02:39.538Z
Reserved: 2019-11-07T00:00:00
Link: CVE-2019-18805
No data.
Status : Modified
Published: 2019-11-07T14:15:11.067
Modified: 2024-11-21T04:33:36.167
Link: CVE-2019-18805
OpenCVE Enrichment
No data.
Weaknesses
EUVD