CVE-2019-8460: OpenBSD

High severity, CVSS 7.5. EPSS: 2.3% chance of exploitation in the next 30 days.

OpenBSD kernel version <= 6.5 can be forced to create long chains of TCP SACK holes that causes very expensive calls to tcp_sack_option() for every incoming SACK packet which can lead to a denial of service.

Affected products

  • OpenBSD OpenBSD: up to and including 6.5

Published 2019-08-26. Last modified 2026-06-17.