Advisory: Support Portal Maintenance. Login is currently unavailable, more info available here.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

[Sophos Advisory]: TCP SACK PANIC kernel vulnerability

Hi everyone,

Three related flaws were found in the Linux kernel’s handling of TCP Selective Acknowledgement (SACK) packets handling with low MSS size. These have been assigned the following CVEs: CVE-2019-11477 is considered an Important severity while CVE-2019-11478 and CVE-2019-11479 are considered a Moderate severity.

The following article outlines the details of the TCP SACK PANIC and how it impacts Sophos products.



This thread was automatically locked due to age.
Parents
  • Is there an approximate release date for v9.604? Really only very rough, next month or more in 3 months?

    -

  • Alex, the article linked to above says the first week of July.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • I see UTM v9.603 is mentioned in the KB Advisory Article for these CVE's, with v9.604 being release mid July to fix it.

     

    Is there a specific SFOS version or versions affected by this for XG appliances?

  • Hi and welcome to the UTM Community!

    My understanding is that all version are affected as this vulnerability was only discovered earlier this month.  In any case, with an XG question, you will want to post in the XG Firewall Community.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply
  • Hi and welcome to the UTM Community!

    My understanding is that all version are affected as this vulnerability was only discovered earlier this month.  In any case, with an XG question, you will want to post in the XG Firewall Community.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Children