CVE-2019-11477, known as SACK Panic, is an integer-overflow vulnerability in the Linux kernel TCP Selective Acknowledgment (SACK) processing path. When processing crafted SACK traffic, fragmented socket buffers can be merged such that the 16-bit TCP segment-count field, tcp_gso_segs, overflows. The overflow can reach a BUG_ON condition in tcp_shifted_skb(), causing a kernel panic.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a Proof-of-Concept (PoC) for CVE-2019-11477 (SACK Panic), a critical Linux kernel vulnerability that can be triggered remotely via crafted TCP SACK packets, leading to a kernel panic (DoS). The PoC is designed for a controlled lab environment and consists of several components: - **apps/**: Contains a custom SSL server (`server.c`, `server.sh`) and client (`client.c`, `client.sh`) that communicate over TLS. The server uses test certificates and serves static content. The client is configured to connect to the server using a domain (www.alice.com) mapped in `/etc/hosts`. - **craft/**: Contains tools (`craft.c`, `tcpopt.c`, `tcpopt.h`) to craft and manipulate TCP packets, specifically to control SACK options and trigger the vulnerability. It uses the Linux netfilter queue to intercept and modify packets. - **module/**: Contains a Linux kernel module (`catcher.c`) that hooks into the netfilter framework to intercept and log relevant TCP traffic on the client, aiding in debugging and analysis. - **include/**: Provides supporting headers, including a local copy of OpenSSL headers for building the client/server applications. - **apps/www.alice.com/**: Contains SSL certificates and a test HTML file for the server. - **sack-debug.diff**: A patch for the Linux kernel source to add debug logging to the SACK code paths, making it easier to observe the effects of the exploit. - **kernel.md**: Instructions for building a vulnerable Linux kernel with the debug patch applied. - **scripts/gen_contents.py**: Utility script to generate test files of arbitrary size. **Purpose:** The repository demonstrates how to trigger and analyze the SACK Panic vulnerability in a safe, reproducible environment. It does not provide a weaponized exploit but rather a research and debugging tool for kernel developers and security researchers. The exploit requires a custom-built vulnerable kernel and is not intended for use against production systems. **Key endpoints and configuration:** - The client targets `www.alice.com` (set in `/etc/hosts`), communicating with the server over a specified port (default 7000). - SSL certificates are provided for secure communication. - The kernel module and crafted packet tools are used to intercept, modify, and analyze TCP traffic to trigger the vulnerability. **Exploit maturity:** This is a Proof-of-Concept (POC) exploit. It demonstrates the vulnerability and provides tools for analysis but does not include a fully automated or weaponized attack chain.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remotely triggerable integer overflow in Linux kernel TCP SACK processing. Crafted SACK segments on a TCP connection with a small MSS can overflow the segment-count variable and crash the kernel, causing denial of service.
An integer-overflow denial-of-service flaw in Linux kernel TCP SACK processing. Crafted SACK segments on a low-MSS TCP connection can crash the kernel remotely.
A Linux kernel TCP SACK processing integer-overflow vulnerability that permits a remote attacker to crash the kernel and cause denial of service using crafted SACK segments and a small TCP MSS.
A Linux kernel TCP SACK processing integer-overflow flaw that permits a remote attacker to crash the kernel, causing denial of service, through crafted SACK traffic on a connection using a small TCP MSS.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.