ADV190020 — Linux Kernel TCP SACK Denial of Service Vulnerability
Executive Summary
Executive Summary Known vulnerabilities exist in the Linux kernel. These vulnerabilities are documented by the following CVEs: CVE-2019-11477, CVE-2019-11478, and CVE-2019-11479. The purpose of this advisory is to explain the various effects of these vulnerabilities and to provide links to more information. If you are running a Linux kernel in your Azure environment, you should contact the provider of that Linux kernel to understand their recommendation for protecting your installation. See below for a list of popular providers. If you are using Azure Sphere for an IoT product, please see Azure Sphere https://azure.microsoft.com/en-us/updates/update-19-06-for-azure-sphere-public-preview-now-available-for-evaluation/ If you are using Azure Kubernetes Service, please see https://github.com/Azure/AKS/issues/1065 If you are using HD Insight, please see https://azure.microsoft.com/en-us/updates/security-advisory-on-linux-kernel-tcp-vulnerabilities-for-hdinsight-clusters/
Overview
EPSS Score
No EPSS score available for this CVE.
View on FIRST.orgAffected Products
| Product | KB Article | Severity | Impact | Restart Required |
|---|---|---|---|---|
| None affected | — |
Unknown | Unknown | Unknown |
Patches
| Article | Type | Restart |
|---|---|---|
— |
Unknown |
Known Exploits
Acknowledgments
Microsoft has not published researcher acknowledgments for this CVE, or they are not yet reflected in our data source. Check the MSRC advisory directly for the most current credit information.