CVE-2019-11477: Canonical Ubuntu Linux
High severity, CVSS 7.5. EPSS: 98.7% chance of exploitation in the next 30 days.
Jonathan Looney discovered that the TCP_SKB_CB(skb)->tcp_gso_segs value was subject to an integer overflow in the Linux kernel when handling TCP Selective Acknowledgments (SACKs). A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11, and is fixed in commit 3b4929f65b0d8249f19a50245cd88ed1a2f78cff.
Affected products
- Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 16.04 only; version 18.04 only; version 18.10 only; version 19.04 only
- F5 BIG-IP Access Policy Manager: from 11.5.2, up to and including 11.6.4; from 12.1.0, up to and including 12.1.4; from 13.1.0, up to and including 13.1.1; from 14.0.0, up to and including 14.1.0; version 15.0.0 only
- F5 BIG-IP Advanced Firewall Manager: from 11.5.2, up to and including 11.6.4; from 12.1.0, up to and including 12.1.4; from 13.1.0, up to and including 13.1.1; from 14.0.0, up to and including 14.1.0; version 15.0.0 only
- F5 BIG-IP Analytics: from 11.5.2, up to and including 11.6.4; from 12.1.0, up to and including 12.1.4; from 13.1.0, up to and including 13.1.1; from 14.0.0, up to and including 14.1.0; version 15.0.0 only
- F5 BIG-IP Application Acceleration Manager: from 11.5.2, up to and including 11.6.4; from 12.1.0, up to and including 12.1.4; from 13.1.0, up to and including 13.1.1; from 14.0.0, up to and including 14.1.0; version 15.0.0 only
- F5 BIG-IP Application Security Manager: from 11.5.2, up to and including 11.6.4; from 12.1.0, up to and including 12.1.4; from 13.1.0, up to and including 13.1.1; from 14.0.0, up to and including 14.1.0; version 15.0.0 only
- F5 BIG-IP Domain Name System: from 11.5.2, up to and including 11.6.4; from 12.1.0, up to and including 12.1.4; from 13.1.0, up to and including 13.1.1; from 14.0.0, up to and including 14.1.0; version 15.0.0 only
- F5 BIG-IP Edge Gateway: from 11.5.2, up to and including 11.6.4; from 12.1.0, up to and including 12.1.4; from 13.1.0, up to and including 13.1.1; from 14.0.0, up to and including 14.1.0; version 15.0.0 only
- F5 BIG-IP Fraud Protection Service: from 11.5.2, up to and including 11.6.4; from 12.1.0, up to and including 12.1.4; from 13.1.0, up to and including 13.1.1; from 14.0.0, up to and including 14.1.0; version 15.0.0 only
- F5 BIG-IP Global Traffic Manager: from 11.5.2, up to and including 11.6.4; from 12.1.0, up to and including 12.1.4; from 13.1.0, up to and including 13.1.1; from 14.0.0, up to and including 14.1.0; version 15.0.0 only
- F5 BIG-IP Link Controller: from 11.5.2, up to and including 11.6.4; from 12.1.0, up to and including 12.1.4; from 13.1.0, up to and including 13.1.1; from 14.0.0, up to and including 14.1.0; version 15.0.0 only
- F5 BIG-IP Local Traffic Manager: from 11.5.2, up to and including 11.6.4; from 12.1.0, up to and including 12.1.4; from 13.1.0, up to and including 13.1.1; from 14.0.0, up to and including 14.1.0; version 15.0.0 only
- F5 BIG-IP Policy Enforcement Manager: from 11.5.2, up to and including 11.6.4; from 12.1.0, up to and including 12.1.4; from 13.1.0, up to and including 13.1.1; from 14.0.0, up to and including 14.1.0; version 15.0.0 only
- F5 BIG-IP Webaccelerator: from 11.5.2, up to and including 11.6.4; from 12.1.0, up to and including 12.1.4; from 13.1.0, up to and including 13.1.1; from 14.0.0, up to and including 14.1.0; version 15.0.0 only
- F5 Traffix Signaling Delivery Controller: from 5.0.0, up to and including 5.1.0
- Ivanti Connect Secure: affected versions not specified
- Linux Linux Kernel: from 2.6.29, before 3.16.69 (fixed in 3.16.69); from 3.17, before 4.4.182 (fixed in 4.4.182); from 4.5, before 4.9.182 (fixed in 4.9.182); from 4.10, before 4.14.127 (fixed in 4.14.127); from 4.15, before 4.19.52 (fixed in 4.19.52); from 4.20, before 5.1.11 (fixed in 5.1.11)
- Pulse Secure Pulse Policy Secure: affected versions not specified
- Pulse Secure Pulse Secure Virtual Application Delivery Controller: affected versions not specified
- Red Hat Enterprise Linux: version 5.0 only; version 6.0 only; version 7.0 only; version 8.0 only
- Red Hat Enterprise Linux Atomic Host: affected versions not specified
- Red Hat Enterprise Linux Aus: version 6.5 only; version 6.6 only
- Red Hat Enterprise Linux Eus: version 7.4 only; version 7.5 only
- Red Hat Enterprise Mrg: version 2.0 only
Published 2019-06-19. Last modified 2026-06-17.