{"$schema":"https://docs.oasis-open.org/csaf/csaf/v2.1/schema/csaf.json","document":{"category":"csaf_security_advisory","csaf_version":"2.1","title":"TCP SACK PANIC – Kernel Vulnerabilities","distribution":{"tlp":{"label":"CLEAR"}},"publisher":{"category":"vendor","name":"WatchGuard PSIRT","namespace":"https://www.watchguard.com"},"tracking":{"id":"WGSA-2019-00001","status":"final","version":"77","initial_release_date":"2019-06-18T10:00:00+00:00","current_release_date":"2026-07-27T16:18:17.227538+00:00","revision_history":[{"date":"2019-06-18T10:00:00+00:00","number":"77","summary":"Initial release."}]},"references":[{"summary":"vendor-advisory","url":"https://psirt.watchguard.com/WGSA-2019-00001"},{"summary":"cve","url":"https://www.cve.org/CVERecord?id=CVE-2019-11477"},{"summary":"cve","url":"https://www.cve.org/CVERecord?id=CVE-2019-11478"},{"summary":"cve","url":"https://www.cve.org/CVERecord?id=CVE-2019-11479"}],"notes":[{"category":"summary","text":"*Updated September 5 2025: Updated to clarify Fireware OS 12.3.1 Update 2 (FIPS-certified release) resolves this issue*\n\nOn 17 June 2019, Netflix engineering manager Jonathan Looney discovered several vulnerabilities that affect multiple open-source Linux and Unix operating systems. Impacted software kernels include FreeBSD 12 using the RACK TCP Stack, and Linux kernels between versions 2.6.29 and 4.15.\n\nThe most serious of the vulnerabilities could allow an attacker to execute a Denial of Service (DoS) attack by sending specially crafted TCP Selective Acknowledgement (SACK) packets to an affected service.\n\nVarious WatchGuard products and services are affected by this vulnerability. For specific products and services, see below. This article will be updated as WatchGuard releases patches for affected platforms.\n\nThe version of the Linux kernel used in Fireware OS v12.3.1 and older is vulnerable to this issue. Fireware OS v12.5.1 Update 1 and v12.3.1 Update 2 (FIPS-certified release) resolve this vulnerability.\n\nAll WatchGuard Access Point models are affected by this vulnerability.\n\nOn July 2nd, 2019, a software patch was applied to all WatchGuard Wi-Fi Cloud servers and services to mitigate these vulnerabilities in Wi-Fi Cloud. \nOn August 23, 2019, WatchGuard Wi-Fi Cloud v8.8 and AP firmware 8.8.0-179 was released and resolves these vulnerabilities for cloud-managed APs.\n\nCurrently, these vulnerabilities are resolved in AP firmware 8.8.0-179 and higher for AP120, AP320, AP322, AP325, AP327X, and AP420 devices managed by Wi-Fi Cloud or managed locally by a Gateway Controller on a Firebox.\n\nFor legacy AP100, AP102, and AP200 devices, AP firmware 1.2.9.x resolves these vulnerabilities. For legacy AP300 devices, AP firmware 2.0.0.12 resolves these vulnerabilities. These updated AP firmware versions are available from Technical Support. To request the firmware, open a Support case.\n\nWe released Dimension v2.1.2 Update 2 on 27 June 2019 to address this vulnerability. \n\nThe version of the Linux kernel used in the WatchGuard WebBlocker on-premise server is vulnerable to this issue. WatchGuard engineering will introduce a patch to mitigate the vulnerability in an upcoming release.","title":"Summary"}]},"product_tree":{"branches":[{"category":"vendor","name":"WatchGuard","branches":[{"category":"product_name","name":"Fireware OS (Default)","branches":[{"category":"product_version_range","name":"vers >= 12.0, < 12.5.1-b605447","product":{"name":"Fireware OS (Default) vers >= 12.0, < 12.5.1-b605447","product_id":"CSAFPID-46ae0b14-8bdb-41f9-a57b-563a6e76c5c7-default"}}]},{"category":"product_name","name":"Fireware OS (FIPS)","branches":[{"category":"product_version_range","name":"vers >= 12.3.1-b584973, < 12.3.1-b675192","product":{"name":"Fireware OS (FIPS) vers >= 12.3.1-b584973, < 12.3.1-b675192","product_id":"CSAFPID-46ae0b14-8bdb-41f9-a57b-563a6e76c5c7-fips"}}]},{"category":"product_name","name":"Secure Wi-Fi","branches":[{"category":"product_version_range","name":"vers >= 8.0.0, < 8.8.0-179","product":{"name":"Secure Wi-Fi vers >= 8.0.0, < 8.8.0-179","product_id":"CSAFPID-6737224d-68ea-4d9e-80e7-1f38f4c398d8"}}]},{"category":"product_name","name":"Dimension","branches":[{"category":"product_version_range","name":"vers >= 2.0, <= 2.1.2-b596545","product":{"name":"Dimension vers >= 2.0, <= 2.1.2-b596545","product_id":"CSAFPID-d36d565e-228e-4d9a-888a-9be70889d829"}}]}]}]},"vulnerabilities":[{"notes":[{"category":"description","text":"*Updated September 5 2025: Updated to clarify Fireware OS 12.3.1 Update 2 (FIPS-certified release) resolves this issue*\n\nOn 17 June 2019, Netflix engineering manager Jonathan Looney discovered several vulnerabilities that affect multiple open-source Linux and Unix operating systems. Impacted software kernels include FreeBSD 12 using the RACK TCP Stack, and Linux kernels between versions 2.6.29 and 4.15.\n\nThe most serious of the vulnerabilities could allow an attacker to execute a Denial of Service (DoS) attack by sending specially crafted TCP Selective Acknowledgement (SACK) packets to an affected service.\n\nVarious WatchGuard products and services are affected by this vulnerability. For specific products and services, see below. This article will be updated as WatchGuard releases patches for affected platforms.\n\nThe version of the Linux kernel used in Fireware OS v12.3.1 and older is vulnerable to this issue. Fireware OS v12.5.1 Update 1 and v12.3.1 Update 2 (FIPS-certified release) resolve this vulnerability.\n\nAll WatchGuard Access Point models are affected by this vulnerability.\n\nOn July 2nd, 2019, a software patch was applied to all WatchGuard Wi-Fi Cloud servers and services to mitigate these vulnerabilities in Wi-Fi Cloud. \nOn August 23, 2019, WatchGuard Wi-Fi Cloud v8.8 and AP firmware 8.8.0-179 was released and resolves these vulnerabilities for cloud-managed APs.\n\nCurrently, these vulnerabilities are resolved in AP firmware 8.8.0-179 and higher for AP120, AP320, AP322, AP325, AP327X, and AP420 devices managed by Wi-Fi Cloud or managed locally by a Gateway Controller on a Firebox.\n\nFor legacy AP100, AP102, and AP200 devices, AP firmware 1.2.9.x resolves these vulnerabilities. For legacy AP300 devices, AP firmware 2.0.0.12 resolves these vulnerabilities. These updated AP firmware versions are available from Technical Support. To request the firmware, open a Support case.\n\nWe released Dimension v2.1.2 Update 2 on 27 June 2019 to address this vulnerability. \n\nThe version of the Linux kernel used in the WatchGuard WebBlocker on-premise server is vulnerable to this issue. WatchGuard engineering will introduce a patch to mitigate the vulnerability in an upcoming release.","title":"Summary"}],"product_status":{"known_affected":["CSAFPID-46ae0b14-8bdb-41f9-a57b-563a6e76c5c7-default","CSAFPID-46ae0b14-8bdb-41f9-a57b-563a6e76c5c7-fips","CSAFPID-6737224d-68ea-4d9e-80e7-1f38f4c398d8","CSAFPID-d36d565e-228e-4d9a-888a-9be70889d829"]},"cve":"CVE-2019-11477","remediations":[{"category":"vendor_fix","details":"Upgrade to Fireware OS 12.3.1-b675192 or later.","product_ids":["CSAFPID-46ae0b14-8bdb-41f9-a57b-563a6e76c5c7-fips"]},{"category":"vendor_fix","details":"Upgrade to Fireware OS 12.5.1-b605447 or later.","product_ids":["CSAFPID-46ae0b14-8bdb-41f9-a57b-563a6e76c5c7-default"]},{"category":"vendor_fix","details":"Upgrade to Secure Wi-Fi 8.8.0-179 or later.","product_ids":["CSAFPID-6737224d-68ea-4d9e-80e7-1f38f4c398d8"]}]},{"notes":[{"category":"description","text":"*Updated September 5 2025: Updated to clarify Fireware OS 12.3.1 Update 2 (FIPS-certified release) resolves this issue*\n\nOn 17 June 2019, Netflix engineering manager Jonathan Looney discovered several vulnerabilities that affect multiple open-source Linux and Unix operating systems. Impacted software kernels include FreeBSD 12 using the RACK TCP Stack, and Linux kernels between versions 2.6.29 and 4.15.\n\nThe most serious of the vulnerabilities could allow an attacker to execute a Denial of Service (DoS) attack by sending specially crafted TCP Selective Acknowledgement (SACK) packets to an affected service.\n\nVarious WatchGuard products and services are affected by this vulnerability. For specific products and services, see below. This article will be updated as WatchGuard releases patches for affected platforms.\n\nThe version of the Linux kernel used in Fireware OS v12.3.1 and older is vulnerable to this issue. Fireware OS v12.5.1 Update 1 and v12.3.1 Update 2 (FIPS-certified release) resolve this vulnerability.\n\nAll WatchGuard Access Point models are affected by this vulnerability.\n\nOn July 2nd, 2019, a software patch was applied to all WatchGuard Wi-Fi Cloud servers and services to mitigate these vulnerabilities in Wi-Fi Cloud. \nOn August 23, 2019, WatchGuard Wi-Fi Cloud v8.8 and AP firmware 8.8.0-179 was released and resolves these vulnerabilities for cloud-managed APs.\n\nCurrently, these vulnerabilities are resolved in AP firmware 8.8.0-179 and higher for AP120, AP320, AP322, AP325, AP327X, and AP420 devices managed by Wi-Fi Cloud or managed locally by a Gateway Controller on a Firebox.\n\nFor legacy AP100, AP102, and AP200 devices, AP firmware 1.2.9.x resolves these vulnerabilities. For legacy AP300 devices, AP firmware 2.0.0.12 resolves these vulnerabilities. These updated AP firmware versions are available from Technical Support. To request the firmware, open a Support case.\n\nWe released Dimension v2.1.2 Update 2 on 27 June 2019 to address this vulnerability. \n\nThe version of the Linux kernel used in the WatchGuard WebBlocker on-premise server is vulnerable to this issue. WatchGuard engineering will introduce a patch to mitigate the vulnerability in an upcoming release.","title":"Summary"}],"product_status":{"known_affected":["CSAFPID-46ae0b14-8bdb-41f9-a57b-563a6e76c5c7-default","CSAFPID-46ae0b14-8bdb-41f9-a57b-563a6e76c5c7-fips","CSAFPID-6737224d-68ea-4d9e-80e7-1f38f4c398d8","CSAFPID-d36d565e-228e-4d9a-888a-9be70889d829"]},"cve":"CVE-2019-11478","remediations":[{"category":"vendor_fix","details":"Upgrade to Fireware OS 12.3.1-b675192 or later.","product_ids":["CSAFPID-46ae0b14-8bdb-41f9-a57b-563a6e76c5c7-fips"]},{"category":"vendor_fix","details":"Upgrade to Fireware OS 12.5.1-b605447 or later.","product_ids":["CSAFPID-46ae0b14-8bdb-41f9-a57b-563a6e76c5c7-default"]},{"category":"vendor_fix","details":"Upgrade to Secure Wi-Fi 8.8.0-179 or later.","product_ids":["CSAFPID-6737224d-68ea-4d9e-80e7-1f38f4c398d8"]}]},{"notes":[{"category":"description","text":"*Updated September 5 2025: Updated to clarify Fireware OS 12.3.1 Update 2 (FIPS-certified release) resolves this issue*\n\nOn 17 June 2019, Netflix engineering manager Jonathan Looney discovered several vulnerabilities that affect multiple open-source Linux and Unix operating systems. Impacted software kernels include FreeBSD 12 using the RACK TCP Stack, and Linux kernels between versions 2.6.29 and 4.15.\n\nThe most serious of the vulnerabilities could allow an attacker to execute a Denial of Service (DoS) attack by sending specially crafted TCP Selective Acknowledgement (SACK) packets to an affected service.\n\nVarious WatchGuard products and services are affected by this vulnerability. For specific products and services, see below. This article will be updated as WatchGuard releases patches for affected platforms.\n\nThe version of the Linux kernel used in Fireware OS v12.3.1 and older is vulnerable to this issue. Fireware OS v12.5.1 Update 1 and v12.3.1 Update 2 (FIPS-certified release) resolve this vulnerability.\n\nAll WatchGuard Access Point models are affected by this vulnerability.\n\nOn July 2nd, 2019, a software patch was applied to all WatchGuard Wi-Fi Cloud servers and services to mitigate these vulnerabilities in Wi-Fi Cloud. \nOn August 23, 2019, WatchGuard Wi-Fi Cloud v8.8 and AP firmware 8.8.0-179 was released and resolves these vulnerabilities for cloud-managed APs.\n\nCurrently, these vulnerabilities are resolved in AP firmware 8.8.0-179 and higher for AP120, AP320, AP322, AP325, AP327X, and AP420 devices managed by Wi-Fi Cloud or managed locally by a Gateway Controller on a Firebox.\n\nFor legacy AP100, AP102, and AP200 devices, AP firmware 1.2.9.x resolves these vulnerabilities. For legacy AP300 devices, AP firmware 2.0.0.12 resolves these vulnerabilities. These updated AP firmware versions are available from Technical Support. To request the firmware, open a Support case.\n\nWe released Dimension v2.1.2 Update 2 on 27 June 2019 to address this vulnerability. \n\nThe version of the Linux kernel used in the WatchGuard WebBlocker on-premise server is vulnerable to this issue. WatchGuard engineering will introduce a patch to mitigate the vulnerability in an upcoming release.","title":"Summary"}],"product_status":{"known_affected":["CSAFPID-46ae0b14-8bdb-41f9-a57b-563a6e76c5c7-default","CSAFPID-46ae0b14-8bdb-41f9-a57b-563a6e76c5c7-fips","CSAFPID-6737224d-68ea-4d9e-80e7-1f38f4c398d8","CSAFPID-d36d565e-228e-4d9a-888a-9be70889d829"]},"cve":"CVE-2019-11479","remediations":[{"category":"vendor_fix","details":"Upgrade to Fireware OS 12.3.1-b675192 or later.","product_ids":["CSAFPID-46ae0b14-8bdb-41f9-a57b-563a6e76c5c7-fips"]},{"category":"vendor_fix","details":"Upgrade to Fireware OS 12.5.1-b605447 or later.","product_ids":["CSAFPID-46ae0b14-8bdb-41f9-a57b-563a6e76c5c7-default"]},{"category":"vendor_fix","details":"Upgrade to Secure Wi-Fi 8.8.0-179 or later.","product_ids":["CSAFPID-6737224d-68ea-4d9e-80e7-1f38f4c398d8"]}]}]}