ID

VAR-201906-1176


CVE

CVE-2019-11478


TITLE

Linux kernel Resource Management Error Vulnerability

Trust: 0.6

sources: CNNVD: CNNVD-201906-682

DESCRIPTION

Jonathan Looney discovered that the TCP retransmission queue implementation in tcp_fragment in the Linux kernel could be fragmented when handling certain TCP Selective Acknowledgment (SACK) sequences. A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11, and is fixed in commit f070ef2ac66716357066b683fb0baf55f8191a2e. This vulnerability stems from improper management of system resources (such as memory, disk space, files, etc.) by network systems or products. A successful exploit could cause the targeted system to crash, resulting in a DoS condition. Proof-of-concept (PoC) code that demonstrates an exploit of this vulnerability is publicly available. Kernel.org has confirmed the vulnerability and released software updates. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: kernel security, bug fix, and enhancement update Advisory ID: RHSA-2019:1483-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2019:1483 Issue date: 2019-06-17 CVE Names: CVE-2018-7566 CVE-2018-1000004 CVE-2019-11477 CVE-2019-11478 CVE-2019-11479 ==================================================================== 1. Summary: An update for kernel is now available for Red Hat Enterprise Linux 7.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux ComputeNode EUS (v. 7.4) - noarch, x86_64 Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.4) - x86_64 Red Hat Enterprise Linux Server EUS (v. 7.4) - noarch, ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Server Optional EUS (v. 7.4) - ppc64, ppc64le, x86_64 3. Description: The kernel packages contain the Linux kernel, the core of any Linux operating system. While processing SACK segments, the Linux kernel's socket buffer (SKB) data structure becomes fragmented. Each fragment is about TCP maximum segment size (MSS) bytes. To efficiently process SACK blocks, the Linux kernel merges multiple fragmented SKBs into one, potentially overflowing the variable holding the number of segments. A remote attacker could use this flaw to crash the Linux kernel by sending a crafted sequence of SACK segments on a TCP connection with small value of TCP MSS, resulting in a denial of service (DoS). (CVE-2019-11477) * kernel: race condition in snd_seq_write() may lead to UAF or OOB-access (CVE-2018-7566) * kernel: Race condition in sound system can lead to denial of service (CVE-2018-1000004) * Kernel: tcp: excessive resource consumption while processing SACK blocks allows remote denial of service (CVE-2019-11478) * Kernel: tcp: excessive resource consumption for TCP connections with low MSS allows remote denial of service (CVE-2019-11479) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Bug Fix(es): * Mistmach between 'tty->termios->c_lflag' and 'ldata->icanon' for 'ICANON' (BZ#1708061) * RHEL7: rwsem reader/writer mutual exclusion guarantee may not work (BZ#1709702) * hardened usercopy is causing crash (BZ#1712311) * [RHEL7] md_clear flag missing from /proc/cpuinfo on late microcode update (BZ#1712991) * [RHEL7] MDS mitigations are not enabled after double microcode update (BZ#1712996) * WARNING: CPU: 0 PID: 0 at kernel/jump_label.c:90 __static_key_slow_dec+0xa6/0xb0 (BZ#1713002) * [debug kernel] [x86_64]INFO: possible circular locking dependency detected (BZ#1715326) * RHEL-7.7: tty: termios_rwsem possible deadlock (BZ#1715329) Enhancement(s): * [MCHP 7.7 FEAT] Update smartpqi driver to latest upstream (BZ#1709467) 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 1535315 - CVE-2018-1000004 kernel: Race condition in sound system can lead to denial of service 1550142 - CVE-2018-7566 kernel: race condition in snd_seq_write() may lead to UAF or OOB-access 1719123 - CVE-2019-11477 Kernel: tcp: integer overflow while processing SACK blocks allows remote denial of service 1719128 - CVE-2019-11478 Kernel: tcp: excessive resource consumption while processing SACK blocks allows remote denial of service 1719129 - CVE-2019-11479 Kernel: tcp: excessive resource consumption for TCP connections with low MSS allows remote denial of service 6. Package List: Red Hat Enterprise Linux ComputeNode EUS (v. 7.4): Source: kernel-3.10.0-693.50.3.el7.src.rpm noarch: kernel-abi-whitelists-3.10.0-693.50.3.el7.noarch.rpm kernel-doc-3.10.0-693.50.3.el7.noarch.rpm x86_64: kernel-3.10.0-693.50.3.el7.x86_64.rpm kernel-debug-3.10.0-693.50.3.el7.x86_64.rpm kernel-debug-debuginfo-3.10.0-693.50.3.el7.x86_64.rpm kernel-debug-devel-3.10.0-693.50.3.el7.x86_64.rpm kernel-debuginfo-3.10.0-693.50.3.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-693.50.3.el7.x86_64.rpm kernel-devel-3.10.0-693.50.3.el7.x86_64.rpm kernel-headers-3.10.0-693.50.3.el7.x86_64.rpm kernel-tools-3.10.0-693.50.3.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-693.50.3.el7.x86_64.rpm kernel-tools-libs-3.10.0-693.50.3.el7.x86_64.rpm perf-3.10.0-693.50.3.el7.x86_64.rpm perf-debuginfo-3.10.0-693.50.3.el7.x86_64.rpm python-perf-3.10.0-693.50.3.el7.x86_64.rpm python-perf-debuginfo-3.10.0-693.50.3.el7.x86_64.rpm Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.4): x86_64: kernel-debug-debuginfo-3.10.0-693.50.3.el7.x86_64.rpm kernel-debuginfo-3.10.0-693.50.3.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-693.50.3.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-693.50.3.el7.x86_64.rpm kernel-tools-libs-devel-3.10.0-693.50.3.el7.x86_64.rpm perf-debuginfo-3.10.0-693.50.3.el7.x86_64.rpm python-perf-debuginfo-3.10.0-693.50.3.el7.x86_64.rpm Red Hat Enterprise Linux Server EUS (v. 7.4): Source: kernel-3.10.0-693.50.3.el7.src.rpm noarch: kernel-abi-whitelists-3.10.0-693.50.3.el7.noarch.rpm kernel-doc-3.10.0-693.50.3.el7.noarch.rpm ppc64: kernel-3.10.0-693.50.3.el7.ppc64.rpm kernel-bootwrapper-3.10.0-693.50.3.el7.ppc64.rpm kernel-debug-3.10.0-693.50.3.el7.ppc64.rpm kernel-debug-debuginfo-3.10.0-693.50.3.el7.ppc64.rpm kernel-debug-devel-3.10.0-693.50.3.el7.ppc64.rpm kernel-debuginfo-3.10.0-693.50.3.el7.ppc64.rpm kernel-debuginfo-common-ppc64-3.10.0-693.50.3.el7.ppc64.rpm kernel-devel-3.10.0-693.50.3.el7.ppc64.rpm kernel-headers-3.10.0-693.50.3.el7.ppc64.rpm kernel-tools-3.10.0-693.50.3.el7.ppc64.rpm kernel-tools-debuginfo-3.10.0-693.50.3.el7.ppc64.rpm kernel-tools-libs-3.10.0-693.50.3.el7.ppc64.rpm perf-3.10.0-693.50.3.el7.ppc64.rpm perf-debuginfo-3.10.0-693.50.3.el7.ppc64.rpm python-perf-3.10.0-693.50.3.el7.ppc64.rpm python-perf-debuginfo-3.10.0-693.50.3.el7.ppc64.rpm ppc64le: kernel-3.10.0-693.50.3.el7.ppc64le.rpm kernel-bootwrapper-3.10.0-693.50.3.el7.ppc64le.rpm kernel-debug-3.10.0-693.50.3.el7.ppc64le.rpm kernel-debug-debuginfo-3.10.0-693.50.3.el7.ppc64le.rpm kernel-debuginfo-3.10.0-693.50.3.el7.ppc64le.rpm kernel-debuginfo-common-ppc64le-3.10.0-693.50.3.el7.ppc64le.rpm kernel-devel-3.10.0-693.50.3.el7.ppc64le.rpm kernel-headers-3.10.0-693.50.3.el7.ppc64le.rpm kernel-tools-3.10.0-693.50.3.el7.ppc64le.rpm kernel-tools-debuginfo-3.10.0-693.50.3.el7.ppc64le.rpm kernel-tools-libs-3.10.0-693.50.3.el7.ppc64le.rpm perf-3.10.0-693.50.3.el7.ppc64le.rpm perf-debuginfo-3.10.0-693.50.3.el7.ppc64le.rpm python-perf-3.10.0-693.50.3.el7.ppc64le.rpm python-perf-debuginfo-3.10.0-693.50.3.el7.ppc64le.rpm s390x: kernel-3.10.0-693.50.3.el7.s390x.rpm kernel-debug-3.10.0-693.50.3.el7.s390x.rpm kernel-debug-debuginfo-3.10.0-693.50.3.el7.s390x.rpm kernel-debug-devel-3.10.0-693.50.3.el7.s390x.rpm kernel-debuginfo-3.10.0-693.50.3.el7.s390x.rpm kernel-debuginfo-common-s390x-3.10.0-693.50.3.el7.s390x.rpm kernel-devel-3.10.0-693.50.3.el7.s390x.rpm kernel-headers-3.10.0-693.50.3.el7.s390x.rpm kernel-kdump-3.10.0-693.50.3.el7.s390x.rpm kernel-kdump-debuginfo-3.10.0-693.50.3.el7.s390x.rpm kernel-kdump-devel-3.10.0-693.50.3.el7.s390x.rpm perf-3.10.0-693.50.3.el7.s390x.rpm perf-debuginfo-3.10.0-693.50.3.el7.s390x.rpm python-perf-3.10.0-693.50.3.el7.s390x.rpm python-perf-debuginfo-3.10.0-693.50.3.el7.s390x.rpm x86_64: kernel-3.10.0-693.50.3.el7.x86_64.rpm kernel-debug-3.10.0-693.50.3.el7.x86_64.rpm kernel-debug-debuginfo-3.10.0-693.50.3.el7.x86_64.rpm kernel-debug-devel-3.10.0-693.50.3.el7.x86_64.rpm kernel-debuginfo-3.10.0-693.50.3.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-693.50.3.el7.x86_64.rpm kernel-devel-3.10.0-693.50.3.el7.x86_64.rpm kernel-headers-3.10.0-693.50.3.el7.x86_64.rpm kernel-tools-3.10.0-693.50.3.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-693.50.3.el7.x86_64.rpm kernel-tools-libs-3.10.0-693.50.3.el7.x86_64.rpm perf-3.10.0-693.50.3.el7.x86_64.rpm perf-debuginfo-3.10.0-693.50.3.el7.x86_64.rpm python-perf-3.10.0-693.50.3.el7.x86_64.rpm python-perf-debuginfo-3.10.0-693.50.3.el7.x86_64.rpm Red Hat Enterprise Linux Server Optional EUS (v. 7.4): ppc64: kernel-debug-debuginfo-3.10.0-693.50.3.el7.ppc64.rpm kernel-debuginfo-3.10.0-693.50.3.el7.ppc64.rpm kernel-debuginfo-common-ppc64-3.10.0-693.50.3.el7.ppc64.rpm kernel-tools-debuginfo-3.10.0-693.50.3.el7.ppc64.rpm kernel-tools-libs-devel-3.10.0-693.50.3.el7.ppc64.rpm perf-debuginfo-3.10.0-693.50.3.el7.ppc64.rpm python-perf-debuginfo-3.10.0-693.50.3.el7.ppc64.rpm ppc64le: kernel-debug-debuginfo-3.10.0-693.50.3.el7.ppc64le.rpm kernel-debug-devel-3.10.0-693.50.3.el7.ppc64le.rpm kernel-debuginfo-3.10.0-693.50.3.el7.ppc64le.rpm kernel-debuginfo-common-ppc64le-3.10.0-693.50.3.el7.ppc64le.rpm kernel-tools-debuginfo-3.10.0-693.50.3.el7.ppc64le.rpm kernel-tools-libs-devel-3.10.0-693.50.3.el7.ppc64le.rpm perf-debuginfo-3.10.0-693.50.3.el7.ppc64le.rpm python-perf-debuginfo-3.10.0-693.50.3.el7.ppc64le.rpm x86_64: kernel-debug-debuginfo-3.10.0-693.50.3.el7.x86_64.rpm kernel-debuginfo-3.10.0-693.50.3.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-693.50.3.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-693.50.3.el7.x86_64.rpm kernel-tools-libs-devel-3.10.0-693.50.3.el7.x86_64.rpm perf-debuginfo-3.10.0-693.50.3.el7.x86_64.rpm python-perf-debuginfo-3.10.0-693.50.3.el7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2018-7566 https://access.redhat.com/security/cve/CVE-2018-1000004 https://access.redhat.com/security/cve/CVE-2019-11477 https://access.redhat.com/security/cve/CVE-2019-11478 https://access.redhat.com/security/cve/CVE-2019-11479 https://access.redhat.com/security/updates/classification/#important https://access.redhat.com/security/vulnerabilities/tcpsack 8. Contact: The Red Hat security contact is <secalert@redhat.com>. More contact details at https://access.redhat.com/security/team/contact/ Copyright 2019 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBXQflkNzjgjWX9erEAQiYBQ/8CqPgl6Z1FdlIkiIKctrTNxBA3HHwyY7j LQBGs4iRnTNxAHYafa1UyeF8nW5wB7x/KTiktC4bu4tur5xGbCuVsQAQX2/YeQHZ cEK3uU4N4wX31sJJmOki5qmnsW28fr1AuT0hfgL8/OWkf+eec66Momg8ZGS9MZ2X 2YJ8kzrE1dBBbBtzvNZDmAC/1i+VsalIObblsI1dIr+753oYnoP0x6WuPn1c7lod CbvPOQvfYB+0b/HNHhRxCOl4ay5NAYC/eCFx9h1JTPoQ/CzzjHwNBm2+HL+Lt+Av A1Ufnm4XBO/lyT1f9bvDiE9xHFP3wzN9hebQvvp4maAFbVPP7upqnCRESm9Ojzew k8n/UHgyWciTgEM79tQ+0Jx4r+k5KQT12mr023SEeRBCNd8H0odfN2SpwGwu39lz P1AwJhN9LddTfO3IOx2RZJcnshaIOhbDBuFW1GBUYgODsGd3RgUqVblryb53IVFG 6jHcYMetblt6dIAhTVtBUTOeVaG/rUkjuWaIKYhNjijgqUdQBGDDJWxK2E/hx+nq r5fgReLwxPz+q27cu70chK9lSa0RAUr3qgCOa+UYfqm3/LclXtPCI/z/YCESE5tc xSZyAhsRDEIgAsNO8neeG68HMX1JZCqun+HnHvcrmh7t2vXM/HRJl7ihp9md2au+ LbgoNJu99kM=aVva -----END PGP SIGNATURE----- -- RHSA-announce mailing list RHSA-announce@redhat.com https://www.redhat.com/mailman/listinfo/rhsa-announce . ========================================================================== Kernel Live Patch Security Notice 0055-1 September 06, 2019 linux vulnerability ========================================================================== A security issue affects these releases of Ubuntu: | Series | Base kernel | Arch | flavors | |------------------+--------------+----------+------------------| | Ubuntu 18.04 LTS | 4.15.0 | amd64 | generic | | Ubuntu 18.04 LTS | 4.15.0 | amd64 | lowlatency | | Ubuntu 16.04 LTS | 4.4.0 | amd64 | generic | | Ubuntu 16.04 LTS | 4.4.0 | amd64 | lowlatency | | Ubuntu 16.04 LTS | 4.15.0 | amd64 | generic | | Ubuntu 16.04 LTS | 4.15.0 | amd64 | lowlatency | Summary: Several security issues were fixed in the kernel. (CVE-2018-20856) It was discovered that the Bluetooth UART implementation in the Linux kernel did not properly check for missing tty operations. (CVE-2019-11478) Jann Horn discovered a use-after-free vulnerability in the Linux kernel when accessing LDT entries in some situations. (CVE-2019-13233) It was discovered that the floppy driver in the Linux kernel did not properly validate meta data, leading to a buffer overread. (CVE-2019-14283) It was discovered that the floppy driver in the Linux kernel did not properly validate ioctl() calls, leading to a division-by-zero. (CVE-2019-14284) Update instructions: The problem can be corrected by updating your livepatches to the following versions: | Kernel | Version | flavors | |--------------------------+----------+--------------------------| | 4.4.0-148.174 | 55.1 | lowlatency, generic | | 4.4.0-150.176 | 55.1 | generic, lowlatency | | 4.4.0-151.178 | 55.1 | lowlatency, generic | | 4.4.0-154.181 | 55.1 | lowlatency, generic | | 4.4.0-157.185 | 55.1 | lowlatency | | 4.4.0-159.187 | 55.1 | lowlatency, generic | | 4.15.0-50.54 | 55.1 | generic, lowlatency | | 4.15.0-50.54~16.04.1 | 55.1 | generic, lowlatency | | 4.15.0-51.55 | 55.1 | generic, lowlatency | | 4.15.0-51.55~16.04.1 | 55.2 | generic, lowlatency | | 4.15.0-52.56 | 55.1 | lowlatency, generic | | 4.15.0-52.56~16.04.1 | 55.1 | generic, lowlatency | | 4.15.0-54.58 | 55.1 | generic, lowlatency | | 4.15.0-54.58~16.04.1 | 55.1 | generic, lowlatency | | 4.15.0-55.60 | 55.1 | generic, lowlatency | | 4.15.0-58.64 | 55.1 | generic, lowlatency | | 4.15.0-58.64~16.04.1 | 55.1 | lowlatency, generic | Support Information: Kernels older than the levels listed below do not receive livepatch updates. Please upgrade your kernel as soon as possible. | Series | Version | Flavors | |------------------+------------------+--------------------------| | Ubuntu 18.04 LTS | 4.15.0-50 | generic lowlatency | | Ubuntu 16.04 LTS | 4.15.0-50 | generic lowlatency | | Ubuntu 16.04 LTS | 4.4.0-148 | generic lowlatency | | Ubuntu 14.04 LTS | 4.4.0-148 | generic lowlatency | References: CVE-2018-20856, CVE-2019-10207, CVE-2019-11478, CVE-2019-13233, CVE-2019-14283, CVE-2019-14284 -- ubuntu-security-announce mailing list ubuntu-security-announce@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce . 6.5) - x86_64 3. Bug Fix(es): * MDS mitigations not enabled on Intel Skylake CPUs (BZ#1713025) * [RHEL6] md_clear flag missing from /proc/cpuinfo (BZ#1713028) * RHEL6 kernel does not disable SMT with mds=full,nosmt (BZ#1713043) 4. Description: The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements. Bug Fix(es): * kernel-rt: update to the RHEL8.0.z batch#1 source tree (BZ#1704955) 4. 7) - aarch64, noarch, ppc64le 3

Trust: 1.71

sources: NVD: CVE-2019-11478 // VULHUB: VHN-143128 // VULMON: CVE-2019-11478 // PACKETSTORM: 153319 // PACKETSTORM: 154408 // PACKETSTORM: 153346 // PACKETSTORM: 153326 // PACKETSTORM: 153322 // PACKETSTORM: 153325 // PACKETSTORM: 153430

AFFECTED PRODUCTS

vendor:f5model:big-ip domain name systemscope:lteversion:11.6.4

Trust: 1.0

vendor:f5model:big-ip link controllerscope:lteversion:11.6.4

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:gteversion:13.1.0

Trust: 1.0

vendor:f5model:big-ip link controllerscope:eqversion:15.0.0

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:lteversion:13.1.1

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:gteversion:14.0.0

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:gteversion:11.5.2

Trust: 1.0

vendor:f5model:big-ip fraud protection servicescope:lteversion:11.6.4

Trust: 1.0

vendor:canonicalmodel:ubuntu linuxscope:eqversion:19.04

Trust: 1.0

vendor:linuxmodel:kernelscope:gteversion:4.5

Trust: 1.0

vendor:f5model:big-ip webacceleratorscope:gteversion:13.1.0

Trust: 1.0

vendor:f5model:big-ip webacceleratorscope:gteversion:14.0.0

Trust: 1.0

vendor:f5model:big-ip edge gatewayscope:lteversion:12.1.4

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:lteversion:13.1.1

Trust: 1.0

vendor:redhatmodel:enterprise linuxscope:eqversion:7.0

Trust: 1.0

vendor:f5model:big-ip analyticsscope:lteversion:11.6.4

Trust: 1.0

vendor:f5model:big-ip edge gatewayscope:gteversion:11.5.2

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:gteversion:11.5.2

Trust: 1.0

vendor:f5model:big-ip application security managerscope:lteversion:12.1.4

Trust: 1.0

vendor:f5model:big-ip webacceleratorscope:lteversion:14.1.0

Trust: 1.0

vendor:f5model:big-ip application security managerscope:gteversion:11.5.2

Trust: 1.0

vendor:linuxmodel:kernelscope:ltversion:4.14.127

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:lteversion:13.1.1

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:lteversion:12.1.4

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:gteversion:12.1.0

Trust: 1.0

vendor:f5model:big-ip fraud protection servicescope:lteversion:14.1.0

Trust: 1.0

vendor:linuxmodel:kernelscope:gteversion:4.15

Trust: 1.0

vendor:f5model:big-ip fraud protection servicescope:gteversion:13.1.0

Trust: 1.0

vendor:f5model:big-ip webacceleratorscope:gteversion:12.1.0

Trust: 1.0

vendor:f5model:big-ip fraud protection servicescope:gteversion:14.0.0

Trust: 1.0

vendor:f5model:big-ip domain name systemscope:gteversion:11.5.2

Trust: 1.0

vendor:canonicalmodel:ubuntu linuxscope:eqversion:12.04

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:eqversion:15.0.0

Trust: 1.0

vendor:f5model:big-ip link controllerscope:gteversion:11.5.2

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:gteversion:13.1.0

Trust: 1.0

vendor:redhatmodel:enterprise linux eusscope:eqversion:7.4

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:gteversion:14.0.0

Trust: 1.0

vendor:f5model:big-ip webacceleratorscope:lteversion:13.1.1

Trust: 1.0

vendor:f5model:big-ip analyticsscope:gteversion:13.1.0

Trust: 1.0

vendor:f5model:big-ip analyticsscope:gteversion:14.0.0

Trust: 1.0

vendor:f5model:big-ip edge gatewayscope:lteversion:11.6.4

Trust: 1.0

vendor:f5model:big-ip domain name systemscope:lteversion:13.1.1

Trust: 1.0

vendor:pulsesecuremodel:pulse policy securescope:eqversion: -

Trust: 1.0

vendor:redhatmodel:enterprise linux eusscope:eqversion:7.5

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:lteversion:14.1.0

Trust: 1.0

vendor:f5model:big-ip link controllerscope:lteversion:13.1.1

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:lteversion:14.1.0

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:gteversion:11.5.2

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:gteversion:13.1.0

Trust: 1.0

vendor:canonicalmodel:ubuntu linuxscope:eqversion:18.04

Trust: 1.0

vendor:linuxmodel:kernelscope:gteversion:4.10

Trust: 1.0

vendor:f5model:big-ip fraud protection servicescope:lteversion:13.1.1

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:gteversion:14.0.0

Trust: 1.0

vendor:f5model:big-ip fraud protection servicescope:gteversion:12.1.0

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:lteversion:14.1.0

Trust: 1.0

vendor:linuxmodel:kernelscope:ltversion:4.9.182

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:gteversion:13.1.0

Trust: 1.0

vendor:f5model:big-ip analyticsscope:lteversion:13.1.1

Trust: 1.0

vendor:f5model:big-ip edge gatewayscope:gteversion:12.1.0

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:gteversion:14.0.0

Trust: 1.0

vendor:redhatmodel:enterprise linuxscope:eqversion:8.0

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:gteversion:12.1.0

Trust: 1.0

vendor:f5model:big-ip edge gatewayscope:lteversion:14.1.0

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:lteversion:12.1.4

Trust: 1.0

vendor:f5model:big-ip analyticsscope:gteversion:12.1.0

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:lteversion:12.1.4

Trust: 1.0

vendor:f5model:big-ip webacceleratorscope:lteversion:11.6.4

Trust: 1.0

vendor:f5model:big-ip application security managerscope:lteversion:14.1.0

Trust: 1.0

vendor:f5model:big-ip application security managerscope:eqversion:15.0.0

Trust: 1.0

vendor:linuxmodel:kernelscope:gteversion:4.20

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:lteversion:14.1.0

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:gteversion:13.1.0

Trust: 1.0

vendor:f5model:big-ip edge gatewayscope:gteversion:13.1.0

Trust: 1.0

vendor:f5model:big-ip edge gatewayscope:gteversion:14.0.0

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:gteversion:14.0.0

Trust: 1.0

vendor:linuxmodel:kernelscope:ltversion:5.1.11

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:gteversion:12.1.0

Trust: 1.0

vendor:redhatmodel:enterprise linux ausscope:eqversion:6.5

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:lteversion:14.1.0

Trust: 1.0

vendor:f5model:big-ip application security managerscope:gteversion:14.0.0

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:lteversion:12.1.4

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:lteversion:14.1.0

Trust: 1.0

vendor:f5model:big-ip domain name systemscope:eqversion:15.0.0

Trust: 1.0

vendor:redhatmodel:enterprise linuxscope:eqversion:6.0

Trust: 1.0

vendor:f5model:big-ip webacceleratorscope:eqversion:15.0.0

Trust: 1.0

vendor:linuxmodel:kernelscope:ltversion:4.19.52

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:gteversion:12.1.0

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:gteversion:11.5.2

Trust: 1.0

vendor:redhatmodel:enterprise linux atomic hostscope:eqversion: -

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:lteversion:12.1.4

Trust: 1.0

vendor:f5model:big-ip edge gatewayscope:lteversion:13.1.1

Trust: 1.0

vendor:redhatmodel:enterprise mrgscope:eqversion:2.0

Trust: 1.0

vendor:f5model:big-ip domain name systemscope:gteversion:13.1.0

Trust: 1.0

vendor:f5model:big-ip fraud protection servicescope:eqversion:15.0.0

Trust: 1.0

vendor:f5model:big-ip application security managerscope:lteversion:13.1.1

Trust: 1.0

vendor:f5model:big-ip domain name systemscope:gteversion:14.0.0

Trust: 1.0

vendor:canonicalmodel:ubuntu linuxscope:eqversion:14.04

Trust: 1.0

vendor:f5model:big-ip link controllerscope:gteversion:13.1.0

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:gteversion:12.1.0

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:lteversion:12.1.4

Trust: 1.0

vendor:f5model:big-ip link controllerscope:gteversion:14.0.0

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:lteversion:11.6.4

Trust: 1.0

vendor:linuxmodel:kernelscope:ltversion:4.4.182

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:gteversion:11.5.2

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:lteversion:11.6.4

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:eqversion:15.0.0

Trust: 1.0

vendor:f5model:big-ip application security managerscope:gteversion:12.1.0

Trust: 1.0

vendor:f5model:big-ip domain name systemscope:lteversion:14.1.0

Trust: 1.0

vendor:f5model:traffix signaling delivery controllerscope:lteversion:5.1.0

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:lteversion:13.1.1

Trust: 1.0

vendor:f5model:big-ip link controllerscope:lteversion:14.1.0

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:gteversion:13.1.0

Trust: 1.0

vendor:f5model:big-ip webacceleratorscope:gteversion:11.5.2

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:gteversion:14.0.0

Trust: 1.0

vendor:f5model:traffix signaling delivery controllerscope:gteversion:5.0.0

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:lteversion:11.6.4

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:eqversion:15.0.0

Trust: 1.0

vendor:f5model:big-ip domain name systemscope:gteversion:12.1.0

Trust: 1.0

vendor:f5model:big-ip analyticsscope:lteversion:14.1.0

Trust: 1.0

vendor:f5model:big-ip analyticsscope:eqversion:15.0.0

Trust: 1.0

vendor:f5model:big-ip webacceleratorscope:lteversion:12.1.4

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:lteversion:11.6.4

Trust: 1.0

vendor:f5model:big-ip application security managerscope:lteversion:11.6.4

Trust: 1.0

vendor:f5model:big-ip link controllerscope:gteversion:12.1.0

Trust: 1.0

vendor:f5model:big-ip domain name systemscope:lteversion:12.1.4

Trust: 1.0

vendor:redhatmodel:enterprise linuxscope:eqversion:5.0

Trust: 1.0

vendor:pulsesecuremodel:pulse secure virtual application delivery controllerscope:eqversion: -

Trust: 1.0

vendor:f5model:big-ip link controllerscope:lteversion:12.1.4

Trust: 1.0

vendor:ivantimodel:connect securescope:eqversion: -

Trust: 1.0

vendor:f5model:big-ip fraud protection servicescope:lteversion:12.1.4

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:lteversion:11.6.4

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:gteversion:12.1.0

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:lteversion:11.6.4

Trust: 1.0

vendor:f5model:big-ip fraud protection servicescope:gteversion:11.5.2

Trust: 1.0

vendor:f5model:big-ip edge gatewayscope:eqversion:15.0.0

Trust: 1.0

vendor:canonicalmodel:ubuntu linuxscope:eqversion:16.04

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:eqversion:15.0.0

Trust: 1.0

vendor:f5model:big-ip analyticsscope:lteversion:12.1.4

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:gteversion:11.5.2

Trust: 1.0

vendor:redhatmodel:enterprise linux ausscope:eqversion:6.6

Trust: 1.0

vendor:f5model:big-ip analyticsscope:gteversion:11.5.2

Trust: 1.0

vendor:canonicalmodel:ubuntu linuxscope:eqversion:18.10

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:eqversion:15.0.0

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:lteversion:13.1.1

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:lteversion:13.1.1

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:eqversion:15.0.0

Trust: 1.0

vendor:f5model:big-ip application security managerscope:gteversion:13.1.0

Trust: 1.0

sources: NVD: CVE-2019-11478

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2019-11478
value: HIGH

Trust: 1.0

security@ubuntu.com: CVE-2019-11478
value: MEDIUM

Trust: 1.0

CNNVD: CNNVD-201906-682
value: HIGH

Trust: 0.6

VULHUB: VHN-143128
value: MEDIUM

Trust: 0.1

VULMON: CVE-2019-11478
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2019-11478
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.1

VULHUB: VHN-143128
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2019-11478
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 3.6
version: 3.0

Trust: 1.0

security@ubuntu.com: CVE-2019-11478
baseSeverity: MEDIUM
baseScore: 5.3
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: LOW
exploitabilityScore: 3.9
impactScore: 1.4
version: 3.0

Trust: 1.0

sources: VULHUB: VHN-143128 // VULMON: CVE-2019-11478 // CNNVD: CNNVD-201906-682 // NVD: CVE-2019-11478 // NVD: CVE-2019-11478

PROBLEMTYPE DATA

problemtype:CWE-400

Trust: 1.1

problemtype:CWE-770

Trust: 1.0

sources: VULHUB: VHN-143128 // NVD: CVE-2019-11478

THREAT TYPE

remote

Trust: 0.7

sources: PACKETSTORM: 153346 // CNNVD: CNNVD-201906-682

TYPE

resource management error

Trust: 0.6

sources: CNNVD: CNNVD-201906-682

PATCH

title:Linux kernel Remediation of resource management error vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=93876

Trust: 0.6

title:Red Hat: Important: redhat-virtualization-host security updateurl:https://vulmon.com/vendoradvisory?qidtp=red_hat_security_advisories&qid=RHSA-20191594 - Security Advisory

Trust: 0.1

title:Red Hat: Important: kernel security and bug fix updateurl:https://vulmon.com/vendoradvisory?qidtp=red_hat_security_advisories&qid=RHSA-20191485 - Security Advisory

Trust: 0.1

title:Red Hat: Important: kernel security and bug fix updateurl:https://vulmon.com/vendoradvisory?qidtp=red_hat_security_advisories&qid=RHSA-20191484 - Security Advisory

Trust: 0.1

title:Red Hat: Important: kernel-rt security and bug fix updateurl:https://vulmon.com/vendoradvisory?qidtp=red_hat_security_advisories&qid=RHSA-20191480 - Security Advisory

Trust: 0.1

title:Ubuntu Security Notice: linux, linux-aws, linux-azure, linux-lts-trusty, linux-lts-xenial vulnerabilitiesurl:https://vulmon.com/vendoradvisory?qidtp=ubuntu_security_notice&qid=USN-4017-2

Trust: 0.1

title:Red Hat: Important: kernel-rt security and bug fix updateurl:https://vulmon.com/vendoradvisory?qidtp=red_hat_security_advisories&qid=RHSA-20191487 - Security Advisory

Trust: 0.1

title:Ubuntu Security Notice: linux, linux-aws, linux-aws-hwe, linux-azure, linux-gcp, linux-hwe, linux-kvm, linux-oem, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilitiesurl:https://vulmon.com/vendoradvisory?qidtp=ubuntu_security_notice&qid=USN-4017-1

Trust: 0.1

title:Red Hat: Important: kernel security updateurl:https://vulmon.com/vendoradvisory?qidtp=red_hat_security_advisories&qid=RHSA-20191482 - Security Advisory

Trust: 0.1

title:Red Hat: Important: kernel-rt security updateurl:https://vulmon.com/vendoradvisory?qidtp=red_hat_security_advisories&qid=RHSA-20191486 - Security Advisory

Trust: 0.1

title:Red Hat: Important: kernel security updateurl:https://vulmon.com/vendoradvisory?qidtp=red_hat_security_advisories&qid=RHSA-20191481 - Security Advisory

Trust: 0.1

title:Debian Security Advisories: DSA-4484-1 linux -- security updateurl:https://vulmon.com/vendoradvisory?qidtp=debian_security_advisories&qid=f7aec913c227117e479ebfa6af2b1b9a

Trust: 0.1

title:Red Hat: CVE-2019-11478url:https://vulmon.com/vendoradvisory?qidtp=red_hat_cve_database&qid=CVE-2019-11478

Trust: 0.1

title:Red Hat: Important: kernel security and bug fix updateurl:https://vulmon.com/vendoradvisory?qidtp=red_hat_security_advisories&qid=RHSA-20191488 - Security Advisory

Trust: 0.1

title:Red Hat: Important: kernel security and bug fix updateurl:https://vulmon.com/vendoradvisory?qidtp=red_hat_security_advisories&qid=RHSA-20191490 - Security Advisory

Trust: 0.1

title:Red Hat: Important: kernel security and bug fix updateurl:https://vulmon.com/vendoradvisory?qidtp=red_hat_security_advisories&qid=RHSA-20191479 - Security Advisory

Trust: 0.1

title:Red Hat: Important: kernel security and bug fix updateurl:https://vulmon.com/vendoradvisory?qidtp=red_hat_security_advisories&qid=RHSA-20191489 - Security Advisory

Trust: 0.1

title:Red Hat: Important: redhat-virtualization-host security and enhancement updateurl:https://vulmon.com/vendoradvisory?qidtp=red_hat_security_advisories&qid=RHSA-20191699 - Security Advisory

Trust: 0.1

title:Red Hat: Important: kernel security, bug fix, and enhancement updateurl:https://vulmon.com/vendoradvisory?qidtp=red_hat_security_advisories&qid=RHSA-20191483 - Security Advisory

Trust: 0.1

title:Arch Linux Issues: url:https://vulmon.com/vendoradvisory?qidtp=arch_linux_issues&qid=CVE-2019-11478

Trust: 0.1

title:Amazon Linux AMI: ALAS-2019-1222url:https://vulmon.com/vendoradvisory?qidtp=amazon_linux_ami&qid=ALAS-2019-1222

Trust: 0.1

title:Arch Linux Advisories: [ASA-201906-12] linux-hardened: denial of serviceurl:https://vulmon.com/vendoradvisory?qidtp=arch_linux_advisories&qid=ASA-201906-12

Trust: 0.1

title:Amazon Linux 2: ALAS2-2019-1222url:https://vulmon.com/vendoradvisory?qidtp=amazon_linux2&qid=ALAS2-2019-1222

Trust: 0.1

title:Arch Linux Advisories: [ASA-201906-15] linux-zen: denial of serviceurl:https://vulmon.com/vendoradvisory?qidtp=arch_linux_advisories&qid=ASA-201906-15

Trust: 0.1

title:Arch Linux Advisories: [ASA-201906-14] linux-lts: denial of serviceurl:https://vulmon.com/vendoradvisory?qidtp=arch_linux_advisories&qid=ASA-201906-14

Trust: 0.1

title:Arch Linux Advisories: [ASA-201906-13] linux: denial of serviceurl:https://vulmon.com/vendoradvisory?qidtp=arch_linux_advisories&qid=ASA-201906-13

Trust: 0.1

title:IBM: Security Bulletin: Multiple Vulnerabilities in the Linux kernel affect the IBM FlashSystem models 840 and 900url:https://vulmon.com/vendoradvisory?qidtp=ibm_psirt_blog&qid=b0e404260719b6ae04a48fa01fe4ff1d

Trust: 0.1

title:IBM: Security Bulletin: Multiple Vulnerabilities in the Linux kernel affect the IBM FlashSystem models V840 and V9000url:https://vulmon.com/vendoradvisory?qidtp=ibm_psirt_blog&qid=17e4e6718a6d3a42ddb3642e1aa88aaf

Trust: 0.1

title:IBM: IBM Security Bulletin: IBM MQ Appliance is affected by kernel vulnerabilities (CVE-2019-11479, CVE-2019-11478 and CVE-2019-11477)url:https://vulmon.com/vendoradvisory?qidtp=ibm_psirt_blog&qid=3abb37d34c3aab5be030484842a197cf

Trust: 0.1

title:IBM: IBM Security Bulletin: Linux Kernel as used by IBM QRadar SIEM is vulnerable to Denial of Service(CVE-2019-11477, CVE-2019-11478, CVE-2019-11479)url:https://vulmon.com/vendoradvisory?qidtp=ibm_psirt_blog&qid=ac66c3446fcbed558afc45a4f11875b9

Trust: 0.1

title:IBM: IBM Security Bulletin: Linux Kernel as used in IBM QRadar Network Packet Capture is vulnerable to denial of service (CVE-2019-11477, CVE-2019-11478, CVE-2019-11479)url:https://vulmon.com/vendoradvisory?qidtp=ibm_psirt_blog&qid=d4c7bbb6295709432116ceed6c8665d0

Trust: 0.1

title:IBM: IBM Security Bulletin: IBM QRadar Network Security is affected by Linux kernel vulnerabilities (CVE-2019-11479, CVE-2019-11478, CVE-2019-11477)url:https://vulmon.com/vendoradvisory?qidtp=ibm_psirt_blog&qid=bae5fea992c13f587f4c457e2320189d

Trust: 0.1

title:IBM: IBM Security Bulletin: IBM Cloud Kubernetes Service is affected by Linux Kernel security vulnerabilities (CVE-2019-11477, CVE-2019-11478, CVE-2019-11479)url:https://vulmon.com/vendoradvisory?qidtp=ibm_psirt_blog&qid=c19eb1501fe75f4801786c3ecf1bdfcd

Trust: 0.1

title:IBM: IBM Security Bulletin: Vulnerabilities in kernel affect Power Hardware Management Console (CVE-2019-11479,CVE-2019-11477 and CVE-2019-11478)url:https://vulmon.com/vendoradvisory?qidtp=ibm_psirt_blog&qid=1eb240b9222a3f8a10e0a63fa47e7f24

Trust: 0.1

title:IBM: IBM Security Bulletin: IBM Security QRadar Packet Capture is vulnerable to Denial of Service (CVE-2019-11477, CVE-2019-11478, CVE-2019-11479, CVE-2019-3896)url:https://vulmon.com/vendoradvisory?qidtp=ibm_psirt_blog&qid=1282c74cfb8f7d86371051c0a3c9e604

Trust: 0.1

title:Siemens Security Advisories: Siemens Security Advisoryurl:https://vulmon.com/vendoradvisory?qidtp=siemens_security_advisories&qid=b013e0ae6345849ef39c81d52c9d45cf

Trust: 0.1

title:Citrix Security Bulletins: Citrix SD-WAN Security Updateurl:https://vulmon.com/vendoradvisory?qidtp=citrix_security_bulletins&qid=fa8566afabfba193549f3f15c0c81ff5

Trust: 0.1

title:IBM: Security Bulletin: Vulnerabilities have been identified in OpenSSL and the Kernel shipped with the DS8000 Hardware Management Console (HMC)url:https://vulmon.com/vendoradvisory?qidtp=ibm_psirt_blog&qid=423d1da688755122eb2591196e4cc160

Trust: 0.1

title:Debian Security Advisories: DSA-4465-1 linux -- security updateurl:https://vulmon.com/vendoradvisory?qidtp=debian_security_advisories&qid=1a396329c4647adcc53e47cd56d6ddad

Trust: 0.1

title:Oracle Linux Bulletins: Oracle Linux Bulletin - July 2019url:https://vulmon.com/vendoradvisory?qidtp=oracle_linux_bulletins&qid=767e8ff3a913d6c9b177c63c24420933

Trust: 0.1

title:Debian CVElist Bug Report Logs: linux-image-4.19.0-4-amd64: CVE-2019-11815url:https://vulmon.com/vendoradvisory?qidtp=debian_cvelist_bugreportlogs&qid=877a1ae1b4d7402bac3b3a0c44e3253b

Trust: 0.1

title:Red Hat: Important: kernel security and bug fix updateurl:https://vulmon.com/vendoradvisory?qidtp=red_hat_security_advisories&qid=RHSA-20200204 - Security Advisory

Trust: 0.1

title:Fortinet Security Advisories: TCP SACK panic attack- Linux Kernel Vulnerabilities- CVE-2019-11477, CVE-2019-11478 & CVE-2019-11479url:https://vulmon.com/vendoradvisory?qidtp=fortinet_security_advisories&qid=FG-IR-19-180

Trust: 0.1

title:IBM: IBM Security Bulletin: IBM Netezza Host Management is affected by the vulnerabilities known as Intel Microarchitectural Data Sampling (MDS) and other Kernel vulnerabilitiesurl:https://vulmon.com/vendoradvisory?qidtp=ibm_psirt_blog&qid=9b0697bf711f12539432f3ec83b074bf

Trust: 0.1

title:IBM: Security Bulletin: Multiple vulnerabilities affect IBM Cloud Object Storage Systems (February 2020v2)url:https://vulmon.com/vendoradvisory?qidtp=ibm_psirt_blog&qid=d9474066c07efdb84c4612586270078f

Trust: 0.1

title:IBM: IBM Security Bulletin: Linux Kernel vulnerabilities affect IBM Spectrum Protect Plus CVE-2019-10140, CVE-2019-11477, CVE-2019-11478, CVE-2019-11479, CVE-2019-13233, CVE-2019-13272, CVE-2019-14283, CVE-2019-14284, CVE-2019-15090, CVE-2019-15807, CVE-2019-15925url:https://vulmon.com/vendoradvisory?qidtp=ibm_psirt_blog&qid=d9cd8f6d11c68af77f2f2bd27ca37bed

Trust: 0.1

title:IBM: IBM Security Bulletin: Multiple Security Vulnerabilities have been addressed in IBM Security Access Manager Applianceurl:https://vulmon.com/vendoradvisory?qidtp=ibm_psirt_blog&qid=800337bc69aa7ad92ac88a2adcc7d426

Trust: 0.1

title:Palo Alto Networks Security Advisory: url:https://vulmon.com/vendoradvisory?qidtp=palo_alto_networks_security_advisory&qid=e4153a9b76a5eea42e73bc20e968375b

Trust: 0.1

title:Palo Alto Networks Security Advisory: PAN-SA-2019-0013 Information about TCP SACK Panic Findings in PAN-OSurl:https://vulmon.com/vendoradvisory?qidtp=palo_alto_networks_security_advisory&qid=57ed3d9f467472d630cb7b7dfca89570

Trust: 0.1

title:IBM: IBM Security Bulletin: Vyatta 5600 vRouter Software Patches – Release 1801-zaurl:https://vulmon.com/vendoradvisory?qidtp=ibm_psirt_blog&qid=8710e4e233940f7482a6adad4643a7a8

Trust: 0.1

title:IBM: IBM Security Bulletin: IBM Security Privileged Identity Manager is affected by multiple security vulnerabilitiesurl:https://vulmon.com/vendoradvisory?qidtp=ibm_psirt_blog&qid=8580d3cd770371e2ef0f68ca624b80b0

Trust: 0.1

title:Siemens Security Advisories: Siemens Security Advisoryurl:https://vulmon.com/vendoradvisory?qidtp=siemens_security_advisories&qid=ec6577109e640dac19a6ddb978afe82d

Trust: 0.1

title:FFFFMurl:https://github.com/misanthropos/FFFFM

Trust: 0.1

title:siteurl:https://github.com/oynqr/site

Trust: 0.1

title:docLinuxurl:https://github.com/hightemp/docLinux

Trust: 0.1

sources: VULMON: CVE-2019-11478 // CNNVD: CNNVD-201906-682

EXTERNAL IDS

db:NVDid:CVE-2019-11478

Trust: 2.5

db:PACKETSTORMid:153346

Trust: 1.8

db:PACKETSTORMid:154408

Trust: 1.8

db:CERT/CCid:VU#905115

Trust: 1.7

db:PACKETSTORMid:154951

Trust: 1.7

db:PULSESECUREid:SA44193

Trust: 1.7

db:SIEMENSid:SSA-462066

Trust: 1.7

db:OPENWALLid:OSS-SECURITY/2019/06/28/2

Trust: 1.7

db:OPENWALLid:OSS-SECURITY/2019/10/29/3

Trust: 1.7

db:OPENWALLid:OSS-SECURITY/2019/10/24/1

Trust: 1.7

db:OPENWALLid:OSS-SECURITY/2019/07/06/4

Trust: 1.7

db:OPENWALLid:OSS-SECURITY/2019/07/06/3

Trust: 1.7

db:ICS CERTid:ICSA-19-253-03

Trust: 1.7

db:MCAFEEid:SB10287

Trust: 1.7

db:CNNVDid:CNNVD-201906-682

Trust: 0.7

db:BIDid:108798

Trust: 0.7

db:PACKETSTORMid:153329

Trust: 0.6

db:AUSCERTid:ESB-2020.3564

Trust: 0.6

db:AUSCERTid:ESB-2019.4528

Trust: 0.6

db:AUSCERTid:ESB-2020.4255

Trust: 0.6

db:AUSCERTid:ESB-2019.2171

Trust: 0.6

db:AUSCERTid:ESB-2020.0736

Trust: 0.6

db:AUSCERTid:ESB-2019.2155

Trust: 0.6

db:AUSCERTid:ESB-2020.0342

Trust: 0.6

db:AUSCERTid:ESB-2019.2231

Trust: 0.6

db:AUSCERTid:ASB-2019.0178.3

Trust: 0.6

db:AUSCERTid:ESB-2019.4316

Trust: 0.6

db:LENOVOid:LEN-29592

Trust: 0.6

db:VULHUBid:VHN-143128

Trust: 0.1

db:VULMONid:CVE-2019-11478

Trust: 0.1

db:PACKETSTORMid:153319

Trust: 0.1

db:PACKETSTORMid:153326

Trust: 0.1

db:PACKETSTORMid:153322

Trust: 0.1

db:PACKETSTORMid:153325

Trust: 0.1

db:PACKETSTORMid:153430

Trust: 0.1

sources: VULHUB: VHN-143128 // VULMON: CVE-2019-11478 // PACKETSTORM: 153319 // PACKETSTORM: 154408 // PACKETSTORM: 153346 // PACKETSTORM: 153326 // PACKETSTORM: 153322 // PACKETSTORM: 153325 // PACKETSTORM: 153430 // CNNVD: CNNVD-201906-682 // NVD: CVE-2019-11478

REFERENCES

url:http://packetstormsecurity.com/files/153346/kernel-live-patch-security-notice-lsn-0052-1.html

Trust: 2.3

url:https://www.us-cert.gov/ics/advisories/icsa-19-253-03

Trust: 2.3

url:https://access.redhat.com/security/vulnerabilities/tcpsack

Trust: 2.2

url:https://access.redhat.com/errata/rhsa-2019:1602

Trust: 1.8

url:https://seclists.org/bugtraq/2019/jul/30

Trust: 1.7

url:https://www.kb.cert.org/vuls/id/905115

Trust: 1.7

url:http://www.arubanetworks.com/assets/alert/aruba-psa-2020-010.txt

Trust: 1.7

url:http://www.vmware.com/security/advisories/vmsa-2019-0010.html

Trust: 1.7

url:https://cert-portal.siemens.com/productcert/pdf/ssa-462066.pdf

Trust: 1.7

url:https://kb.pulsesecure.net/articles/pulse_security_advisories/sa44193

Trust: 1.7

url:https://psirt.global.sonicwall.com/vuln-detail/snwlid-2019-0007

Trust: 1.7

url:https://security.netapp.com/advisory/ntap-20190625-0001/

Trust: 1.7

url:https://support.f5.com/csp/article/k26618426

Trust: 1.7

url:https://www.synology.com/security/advisory/synology_sa_19_28

Trust: 1.7

url:http://packetstormsecurity.com/files/154408/kernel-live-patch-security-notice-lsn-0055-1.html

Trust: 1.7

url:http://packetstormsecurity.com/files/154951/kernel-live-patch-security-notice-lsn-0058-1.html

Trust: 1.7

url:https://git.kernel.org/pub/scm/linux/kernel/git/davem/net.git/commit/?id=f070ef2ac66716357066b683fb0baf55f8191a2e

Trust: 1.7

url:https://github.com/netflix/security-bulletins/blob/master/advisories/third-party/2019-001.md

Trust: 1.7

url:https://wiki.ubuntu.com/securityteam/knowledgebase/sackpanic

Trust: 1.7

url:https://www.oracle.com/security-alerts/cpujan2020.html

Trust: 1.7

url:https://www.oracle.com/security-alerts/cpuoct2020.html

Trust: 1.7

url:http://www.openwall.com/lists/oss-security/2019/06/28/2

Trust: 1.7

url:http://www.openwall.com/lists/oss-security/2019/07/06/3

Trust: 1.7

url:http://www.openwall.com/lists/oss-security/2019/07/06/4

Trust: 1.7

url:http://www.openwall.com/lists/oss-security/2019/10/24/1

Trust: 1.7

url:http://www.openwall.com/lists/oss-security/2019/10/29/3

Trust: 1.7

url:https://access.redhat.com/errata/rhsa-2019:1594

Trust: 1.7

url:https://access.redhat.com/errata/rhsa-2019:1699

Trust: 1.7

url:https://kc.mcafee.com/corporate/index?page=content&id=sb10287

Trust: 1.6

url:https://nvd.nist.gov/vuln/detail/cve-2019-11478

Trust: 1.3

url:https://access.redhat.com/security/cve/cve-2019-11478

Trust: 1.1

url:https://access.redhat.com/errata/rhsa-2019:1483

Trust: 0.7

url:https://access.redhat.com/errata/rhsa-2019:1487

Trust: 0.7

url:https://access.redhat.com/errata/rhsa-2019:1490

Trust: 0.7

url:https://access.redhat.com/errata/rhsa-2019:1480

Trust: 0.7

url:https://nvd.nist.gov/vuln/detail/cve-2019-11477

Trust: 0.6

url:https://access.redhat.com/errata/rhsa-2019:1489

Trust: 0.6

url:https://access.redhat.com/errata/rhsa-2019:1488

Trust: 0.6

url:https://access.redhat.com/errata/rhsa-2019:1486

Trust: 0.6

url:https://access.redhat.com/errata/rhsa-2019:1485

Trust: 0.6

url:https://access.redhat.com/errata/rhsa-2019:1484

Trust: 0.6

url:https://access.redhat.com/errata/rhsa-2019:1482

Trust: 0.6

url:https://access.redhat.com/errata/rhsa-2019:1481

Trust: 0.6

url:https://access.redhat.com/errata/rhsa-2019:1479

Trust: 0.6

url:https://bugzilla.redhat.com/show_bug.cgi?id=1719128

Trust: 0.6

url:http://www.kernel.org/

Trust: 0.6

url:https://usn.ubuntu.com/4017-2

Trust: 0.6

url:https://usn.ubuntu.com/4017-1

Trust: 0.6

url:https://support.citrix.com/article/ctx256725

Trust: 0.6

url:https://www.suse.com/support/update/announcement/2019/suse-su-20191530-1.html

Trust: 0.6

url:https://www.suse.com/support/update/announcement/2019/suse-su-20191529-1.html

Trust: 0.6

url:https://www.suse.com/support/update/announcement/2019/suse-su-20191532-1.html

Trust: 0.6

url:https://www.suse.com/support/update/announcement/2019/suse-su-20191536-1.html

Trust: 0.6

url:https://www.ibm.com/support/pages/node/1284766

Trust: 0.6

url:https://www.ibm.com/support/pages/node/1284760

Trust: 0.6

url:https://www.ibm.com/support/pages/node/1284772

Trust: 0.6

url:https://www.ibm.com/support/pages/node/1284778

Trust: 0.6

url:https://www.ibm.com/support/pages/node/1284784

Trust: 0.6

url:https://www.suse.com/support/update/announcement/2019/suse-su-20191550-1.html

Trust: 0.6

url:https://www.suse.com/support/update/announcement/2019/suse-su-20191535-1.html

Trust: 0.6

url:https://www.suse.com/support/update/announcement/2019/suse-su-20191534-1.html

Trust: 0.6

url:https://www.suse.com/support/update/announcement/2019/suse-su-20191533-1.html

Trust: 0.6

url:https://www.suse.com/support/update/announcement/2019/suse-su-20191527-1.html

Trust: 0.6

url:https://www.suse.com/support/update/announcement/2019/suse-su-201914089-1.html

Trust: 0.6

url:https://www.suse.com/support/update/announcement/2019/suse-su-20191581-1.html

Trust: 0.6

url:https://www.suse.com/support/update/announcement/2019/suse-su-20191588-1.html

Trust: 0.6

url:https://fortiguard.com/psirt/fg-ir-19-180

Trust: 0.6

url:https://vigilance.fr/vulnerability/linux-kernel-denial-of-service-via-tcp-sack-fragmented-retransmission-queue-29544

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2019.4528/

Trust: 0.6

url:https://www.ibm.com/blogs/psirt/security-bulletin-vulnerabilities-have-been-identified-in-openssl-and-the-kernel-shipped-with-the-ds8000-hardware-management-console-hmc/

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2019.4316/

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2020.0736/

Trust: 0.6

url:https://support.lenovo.com/us/en/product_security/len-29592

Trust: 0.6

url:https://packetstormsecurity.com/files/153329/linux-freebsd-tcp-based-denial-of-service.html

Trust: 0.6

url:https://www.ibm.com/support/pages/node/1137796

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2020.4255/

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2019.2231/

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2019.2155/

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2019.2171/

Trust: 0.6

url:https://www.auscert.org.au/bulletins/asb-2019.0178.3/

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2020.0342/

Trust: 0.6

url:https://www.ibm.com/blogs/psirt/security-bulletin-ibm-has-announced-a-release-for-ibm-security-identity-governance-and-intelligence-in-response-to-security-vulnerability-cve-2019-11479-cve-2019-11478-cve-2019-11477/

Trust: 0.6

url:https://www.ibm.com/support/pages/node/3517185

Trust: 0.6

url:https://www.ibm.com/support/pages/node/1164286

Trust: 0.6

url:https://us-cert.cisa.gov/ics/advisories/icsa-19-253-03

Trust: 0.6

url:https://www.ibm.com/blogs/psirt/security-bulletin-ibm-integrated-management-module-ii-imm2-is-affected-by-vulnerabilities-in-tcp-cve-2019-11477-cve-2019-11478-cve-2019-11479/

Trust: 0.6

url:https://www.securityfocus.com/bid/108798

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2020.3564/

Trust: 0.6

url:https://www.ibm.com/blogs/psirt/security-bulletin-ibm-bootable-media-creator-bomc-is-affected-by-vulnerabilities-in-the-kernel/

Trust: 0.6

url:https://www.redhat.com/mailman/listinfo/rhsa-announce

Trust: 0.5

url:https://access.redhat.com/security/cve/cve-2019-11477

Trust: 0.5

url:https://access.redhat.com/security/cve/cve-2019-11479

Trust: 0.5

url:https://bugzilla.redhat.com/):

Trust: 0.5

url:https://access.redhat.com/security/team/key/

Trust: 0.5

url:https://access.redhat.com/articles/11258

Trust: 0.5

url:https://nvd.nist.gov/vuln/detail/cve-2019-11479

Trust: 0.5

url:https://access.redhat.com/security/team/contact/

Trust: 0.5

url:https://access.redhat.com/security/updates/classification/#important

Trust: 0.5

url:https://nvd.nist.gov/vuln/detail/cve-2018-7566

Trust: 0.2

url:https://access.redhat.com/security/cve/cve-2018-1000004

Trust: 0.2

url:https://access.redhat.com/security/cve/cve-2018-7566

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2018-1000004

Trust: 0.2

url:https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

Trust: 0.2

url:https://kc.mcafee.com/corporate/index?page=content&amp;id=sb10287

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-13233

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2018-20856

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-14284

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-14283

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-10207

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2019-3896

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-3896

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-9213

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2019-9213

Trust: 0.1

sources: VULHUB: VHN-143128 // PACKETSTORM: 153319 // PACKETSTORM: 154408 // PACKETSTORM: 153346 // PACKETSTORM: 153326 // PACKETSTORM: 153322 // PACKETSTORM: 153325 // PACKETSTORM: 153430 // CNNVD: CNNVD-201906-682 // NVD: CVE-2019-11478

CREDITS

Jonathan Looney (Netflix Information Security),Jonathan Looney

Trust: 0.6

sources: CNNVD: CNNVD-201906-682

SOURCES

db:VULHUBid:VHN-143128
db:VULMONid:CVE-2019-11478
db:PACKETSTORMid:153319
db:PACKETSTORMid:154408
db:PACKETSTORMid:153346
db:PACKETSTORMid:153326
db:PACKETSTORMid:153322
db:PACKETSTORMid:153325
db:PACKETSTORMid:153430
db:CNNVDid:CNNVD-201906-682
db:NVDid:CVE-2019-11478

LAST UPDATE DATE

2026-03-11T20:24:58.461000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-143128date:2020-10-20T00:00:00
db:VULMONid:CVE-2019-11478date:2023-08-16T00:00:00
db:CNNVDid:CNNVD-201906-682date:2021-12-20T00:00:00
db:NVDid:CVE-2019-11478date:2024-11-21T04:21:09.703

SOURCES RELEASE DATE

db:VULHUBid:VHN-143128date:2019-06-19T00:00:00
db:VULMONid:CVE-2019-11478date:2019-06-19T00:00:00
db:PACKETSTORMid:153319date:2019-06-17T19:16:28
db:PACKETSTORMid:154408date:2019-09-07T13:33:33
db:PACKETSTORMid:153346date:2019-06-19T17:20:41
db:PACKETSTORMid:153326date:2019-06-18T15:44:04
db:PACKETSTORMid:153322date:2019-06-18T15:43:26
db:PACKETSTORMid:153325date:2019-06-18T15:43:55
db:PACKETSTORMid:153430date:2019-06-25T23:50:27
db:CNNVDid:CNNVD-201906-682date:2019-06-18T00:00:00
db:NVDid:CVE-2019-11478date:2019-06-19T00:15:12.687