#VU18947 Resource exhaustion in Linux kernel - CVE-2019-11479
Published: July 1, 2019 / Updated: June 1, 2020
Linux kernel
Linux Foundation
Description
The vulnerability allows a remote attacker to perform denial of service (DoS) attack.
The vulnerability exists due to presence of hard-coded MSS value (48 bytes) in the Linux kernel source code. A remote attacker can fragment TCP resend queues significantly more than if a larger MSS were enforced and perform denial of service (DoS) attack.
Remediation
Update your kernel to the latest version.
External links
- https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.182
- https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.182
- https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.127
- https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.52
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.1.11
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.2