Integer overflow in TCP_SKB_CB(skb)->tcp_gso_segs
No sign of exploitation. No public exploitation artifact known so far.
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
A flaw in how Linux handles TCP data packets allows a remote attacker to send specially crafted network packets that cause the system to crash or stop responding. The issue is in the kernel's handling of a TCP feature called SACK (Selective Acknowledgment).
An integer overflow vulnerability exists in TCP_SKB_CB(skb)->tcp_gso_segs when processing TCP Selective Acknowledgments (SACKs) in the Linux kernel. A remote unauthenticated attacker can trigger this overflow by sending specially crafted TCP packets, leading to denial of service via kernel panic or resource exhaustion. The vulnerability affects kernel versions prior to 4.4.182, 4.9.182, 4.14.127, 4.19.52, and 5.1.11.