An issue was discovered in net/ipv4/sysctl_net_ipv4.c in the Linux kernel before 5.0.11. There is a net/ipv4/tcp_input.c signed integer overflow in tcp_ack_update_rtt() when userspace writes a very large integer to /proc/sys/net/ipv4/tcp_min_rtt_wlen, leading to a denial of service or possibly unspecified other impact, aka CID-19fad20d15a6.
AI analysis not yet available
Plain-English explanation, risk summary, and remediation steps will appear here once AI analysis is complete.
No Fix Known
No patch has been released yet. Apply workarounds or mitigations where available.
| Vendor | Product | Versions | Fixed In |
|---|---|---|---|
| linux | linux_kernel | 4.4 - 4.4.180 | - |
| linux | linux_kernel | 4.9 - 4.9.172 | - |
| linux | linux_kernel | 4.14 - 4.14.115 |
Published
CVE disclosed publicly
Last Modified
Most recent update
Indexed to CVEInsight
Added to this platform
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
29
Affected Products
12
References
linux / linux_kernel
| - |
| linux | linux_kernel | 4.19 - 4.19.38 | - |
| linux | linux_kernel | 5.0 - 5.0.11 | - |
| linux | linux_kernel | - | - |
| linux | linux_kernel | - | - |
| linux | linux_kernel | - | - |
| linux | linux_kernel | - | - |
| linux | linux_kernel | - | - |
| linux | linux_kernel | - | - |
| linux | linux_kernel | - | - |
| opensuse | leap | - | - |
| opensuse | leap | - | - |
| redhat | enterprise_linux | - | - |
| netapp | active_iq_unified_manager | - | - |
| netapp | data_availability_services | - | - |
| netapp | e-series_santricity_os_controller | 11.0.0 - 11.60.3 | - |
| netapp | hci_management_node | - | - |
| netapp | solidfire | - | - |
| netapp | steelstore_cloud_integrated_storage | - | - |
| netapp | hci_compute_node | - | - |
| netapp | hci_storage_node | - | - |
| broadcom | fabric_operating_system | - | - |
| netapp | aff_a700s_firmware | - | - |
| netapp | fas8300_firmware | - | - |
| netapp | fas8700_firmware | - | - |
| netapp | aff_a400_firmware | - | - |
| netapp | h610s_firmware | - | - |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability
Impact