Netflix employees found three vulnerabilities in the TCP network stack code. The most severe of these vulnerabilities allows a remote attacker to trigger a kernel panic.
Several CVE identifiers were assigned to these issues: CVE-2019-11477 classified as a critical vulnerability, along with CVE-2019-11478 and CVE-2019-11479 as moderate.
The first two vulnerabilities relate to SACK (Selective Acknowledgement) and MSS (Maximum Segment Size). The third one only pertains to MSS.
Source: linux.org.ru
