TCP SACK PANIC – Kernel Vulnerabilities
Summary #
*Updated September 5 2025: Updated to clarify Fireware OS 12.3.1 Update 2 (FIPS-certified release) resolves this issue*
On 17 June 2019, Netflix engineering manager Jonathan Looney discovered several vulnerabilities that affect multiple open-source Linux and Unix operating systems. Impacted software kernels include FreeBSD 12 using the RACK TCP Stack, and Linux kernels between versions 2.6.29 and 4.15.
The most serious of the vulnerabilities could allow an attacker to execute a Denial of Service (DoS) attack by sending specially crafted TCP Selective Acknowledgement (SACK) packets to an affected service.
Various WatchGuard products and services are affected by this vulnerability. For specific products and services, see below. This article will be updated as WatchGuard releases patches for affected platforms.
The version of the Linux kernel used in Fireware OS v12.3.1 and older is vulnerable to this issue. Fireware OS v12.5.1 Update 1 and v12.3.1 Update 2 (FIPS-certified release) resolve this vulnerability.
All WatchGuard Access Point models are affected by this vulnerability.
On July 2nd, 2019, a software patch was applied to all WatchGuard Wi-Fi Cloud servers and services to mitigate these vulnerabilities in Wi-Fi Cloud. On August 23, 2019, WatchGuard Wi-Fi Cloud v8.8 and AP firmware 8.8.0-179 was released and resolves these vulnerabilities for cloud-managed APs.
Currently, these vulnerabilities are resolved in AP firmware 8.8.0-179 and higher for AP120, AP320, AP322, AP325, AP327X, and AP420 devices managed by Wi-Fi Cloud or managed locally by a Gateway Controller on a Firebox.
For legacy AP100, AP102, and AP200 devices, AP firmware 1.2.9.x resolves these vulnerabilities. For legacy AP300 devices, AP firmware 2.0.0.12 resolves these vulnerabilities. These updated AP firmware versions are available from Technical Support. To request the firmware, open a Support case.
We released Dimension v2.1.2 Update 2 on 27 June 2019 to address this vulnerability.
The version of the Linux kernel used in the WatchGuard WebBlocker on-premise server is vulnerable to this issue. WatchGuard engineering will introduce a patch to mitigate the vulnerability in an upcoming release.
CVE identifiers #
| CVE ID | Description | CVSS |
|---|---|---|
| CVE-2019-11477 | Jonathan Looney discovered that the TCP_SKB_CB(skb)->tcp_gso_segs value was subject to an integer overflow in the Linux kernel when handling TCP Selective Acknowledgments (SACKs). A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11, and is fixed in commit 3b4929f65b0d8249f19a50245cd88ed1a2f78cff. | 7.5 |
| CVE-2019-11478 | Jonathan Looney discovered that the TCP retransmission queue implementation in tcp_fragment in the Linux kernel could be fragmented when handling certain TCP Selective Acknowledgment (SACK) sequences. A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11, and is fixed in commit f070ef2ac66716357066b683fb0baf55f8191a2e. | 5.3 |
| CVE-2019-11479 | Jonathan Looney discovered that the Linux kernel default MSS is hard-coded to 48 bytes. This allows a remote peer to fragment TCP resend queues significantly more than if a larger MSS were enforced. A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11, and is fixed in commits 967c05aee439e6e5d7d805e195b3a20ef5c433d6 and 5f3e2bf008c2221478101ee72f5cb4654b9fc363. | 5.3 |
Product status #
| Product | Affected | Not affected |
|---|---|---|
| Dimension | >= 2.0, <= 2.1.2-b596545 | > 2.1.2-b596545 |
| Fireware OS | ||
| Default | >= 12.0, < 12.5.1-b605447 | >= 12.5.1-b605447 |
| FIPS | >= 12.3.1-b584973, < 12.3.1-b675192 | >= 12.3.1-b675192 |
| Secure Wi-Fi | >= 8.0.0, < 8.8.0-179 | >= 8.8.0-179 |
Solution #
No solution has been published for this advisory.