{"document":{"category":"csaf_vex","csaf_version":"2.1","notes":[{"category":"summary","text":"Palo Alto Networks PSIRT provided VEX document. This document is autogenerated.","title":"Information about TCP SACK Panic Findings in PAN-OS "}],"publisher":{"category":"vendor","name":"Palo Alto Networks","namespace":"https://security.paloaltonetworks.com"},"title":"Palo Alto Networks PSIRT provided VEX document: PAN-SA-2019-0013","distribution":{"text":"Copyright © 2024 Palo Alto Networks. All rights reserved.","tlp":{"label":"CLEAR","url":"https://www.first.org/tlp/"}},"tracking":{"current_release_date":"2026-07-28T10:49:29.888Z","generator":{"date":"2026-07-28T10:49:29.888Z","engine":{"name":"Vulnogram","version":"0.0.9"}},"id":"PAN-SA-2019-0013","initial_release_date":"2019-06-27T23:50:00.000Z","revision_history":[{"number":"1","date":"2026-07-28T03:49:29.000Z","summary":"Initial release"}],"status":"final","version":"1"}},"product_tree":{"branches":[{"name":"Palo Alto Networks","category":"vendor","branches":[{"name":"PAN-OS","category":"product_name","branches":[{"category":"product_version_range","name":"vers:generic/PAN-OS<=7.1.23","product":{"name":"Palo Alto Networks PAN-OS","product_id":"PANW-PAN-OS-367"}},{"category":"product_version_range","name":"vers:generic/PAN-OS>=7.1.24","product":{"name":"Palo Alto Networks PAN-OS","product_id":"PANW-PAN-OS-357"}},{"category":"product_version_range","name":"vers:generic/PAN-OS<=8.0.18","product":{"name":"Palo Alto Networks PAN-OS","product_id":"PANW-PAN-OS-368"}},{"category":"product_version_range","name":"vers:generic/PAN-OS>=8.0.19","product":{"name":"Palo Alto Networks PAN-OS","product_id":"PANW-PAN-OS-359"}},{"category":"product_version_range","name":"vers:generic/PAN-OS<=8.1.8-h4","product":{"name":"Palo Alto Networks PAN-OS","product_id":"PANW-PAN-OS-369"}},{"category":"product_version_range","name":"vers:generic/PAN-OS>=8.1.8-h5","product":{"name":"Palo Alto Networks PAN-OS","product_id":"PANW-PAN-OS-739"}},{"category":"product_version_range","name":"vers:generic/PAN-OS<=9.0.2-h3","product":{"name":"Palo Alto Networks PAN-OS","product_id":"PANW-PAN-OS-740"}},{"category":"product_version_range","name":"vers:generic/PAN-OS>=9.0.2-h4","product":{"name":"Palo Alto Networks PAN-OS","product_id":"PANW-PAN-OS-741"}}]}]}]},"vulnerabilities":[{"cve":"CVE-2019-11477","product_status":{"fixed":["PANW-PAN-OS-357","PANW-PAN-OS-359","PANW-PAN-OS-739","PANW-PAN-OS-741"],"known_affected":["PANW-PAN-OS-367","PANW-PAN-OS-368","PANW-PAN-OS-369","PANW-PAN-OS-740"]},"notes":[{"category":"description","text":"Jonathan Looney discovered that the TCP_SKB_CB(skb)->tcp_gso_segs value was subject to an integer overflow in the Linux kernel when handling TCP Selective Acknowledgments (SACKs). A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11, and is fixed in commit 3b4929f65b0d8249f19a50245cd88ed1a2f78cff."}],"references":[{"category":"external","summary":"NVD - CVE-2019-11477","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-11477"},{"category":"self","summary":"Palo Alto Networks Security Advisory PAN-SA-2019-0013","url":"https://security.paloaltonetworks.com/PAN-SA-2019-0013"}],"threats":[{"category":"impact","description":"Jonathan Looney discovered that the TCP_SKB_CB(skb)->tcp_gso_segs value was subject to an integer overflow in the Linux kernel when handling TCP Selective Acknowledgments (SACKs). A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11, and is fixed in commit 3b4929f65b0d8249f19a50245cd88ed1a2f78cff."}]},{"cve":"CVE-2019-11478","product_status":{"fixed":["PANW-PAN-OS-357","PANW-PAN-OS-359","PANW-PAN-OS-739","PANW-PAN-OS-741"],"known_affected":["PANW-PAN-OS-367","PANW-PAN-OS-368","PANW-PAN-OS-369","PANW-PAN-OS-740"]},"notes":[{"category":"description","text":"Jonathan Looney discovered that the TCP retransmission queue implementation in tcp_fragment in the Linux kernel could be fragmented when handling certain TCP Selective Acknowledgment (SACK) sequences. A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11, and is fixed in commit f070ef2ac66716357066b683fb0baf55f8191a2e."}],"references":[{"category":"external","summary":"NVD - CVE-2019-11478","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-11478"},{"category":"self","summary":"Palo Alto Networks Security Advisory PAN-SA-2019-0013","url":"https://security.paloaltonetworks.com/PAN-SA-2019-0013"}],"threats":[{"category":"impact","description":"Jonathan Looney discovered that the TCP retransmission queue implementation in tcp_fragment in the Linux kernel could be fragmented when handling certain TCP Selective Acknowledgment (SACK) sequences. A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11, and is fixed in commit f070ef2ac66716357066b683fb0baf55f8191a2e."}]},{"cve":"CVE-2019-11479","product_status":{"fixed":["PANW-PAN-OS-357","PANW-PAN-OS-359","PANW-PAN-OS-739","PANW-PAN-OS-741"],"known_affected":["PANW-PAN-OS-367","PANW-PAN-OS-368","PANW-PAN-OS-369","PANW-PAN-OS-740"]},"notes":[{"category":"description","text":"Jonathan Looney discovered that the Linux kernel default MSS is hard-coded to 48 bytes. This allows a remote peer to fragment TCP resend queues significantly more than if a larger MSS were enforced. A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11, and is fixed in commits 967c05aee439e6e5d7d805e195b3a20ef5c433d6 and 5f3e2bf008c2221478101ee72f5cb4654b9fc363."}],"references":[{"category":"external","summary":"NVD - CVE-2019-11479","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-11479"},{"category":"self","summary":"Palo Alto Networks Security Advisory PAN-SA-2019-0013","url":"https://security.paloaltonetworks.com/PAN-SA-2019-0013"}],"threats":[{"category":"impact","description":"Jonathan Looney discovered that the Linux kernel default MSS is hard-coded to 48 bytes. This allows a remote peer to fragment TCP resend queues significantly more than if a larger MSS were enforced. A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11, and is fixed in commits 967c05aee439e6e5d7d805e195b3a20ef5c433d6 and 5f3e2bf008c2221478101ee72f5cb4654b9fc363."}]}]}