Impact: Moderate Public Date: 2019-05-01 CWE: CWE-119->CWE-125 Bugzilla: 1707358: CVE-2019-11683 kernel: udp_gro_receive_segment in net/ipv4/udp_offload.c allows denial of service or other unspecified impact via UDP packets with 0 payload udp_gro_receive_segment in net/ipv4/udp_offload.c in the Linux kernel 5.x before 5.0.13 allows remote attackers to cause a denial of service (slab-out-of-bounds memory corruption) or possibly have unspecified other impact via UDP packets with a 0 payload, because of mishandling of padded packets, aka the "GRO packet of death" issue.
The MITRE CVE dictionary describes this issue as:
Find out more about CVE-2019-11683 from the MITRE CVE dictionary dictionary and NIST NVD.
This flaw did not affect the versions of kernel as shipped with Red Hat Enterprise Linux 5, 6, 7 and 8.
NOTE: The following CVSS v3 metrics and score provided are preliminary and subject to review.
CVSS3 Base Score | 7.5 |
---|---|
CVSS3 Base Metrics | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Attack Vector | Network |
Attack Complexity | Low |
Privileges Required | None |
User Interaction | None |
Scope | Unchanged |
Confidentiality | None |
Integrity Impact | None |
Availability Impact | High |
Platform | Package | State |
---|---|---|
Red Hat Enterprise MRG 2 | kernel-rt | Not affected |
Red Hat Enterprise Linux 7 | kernel-alt | Not affected |
Red Hat Enterprise Linux 7 | kernel | Not affected |
Red Hat Enterprise Linux 7 | kernel-rt | Not affected |
Red Hat Enterprise Linux 6 | kernel | Not affected |
Red Hat Enterprise Linux 5 | kernel | Not affected |