---
title: Ubuntu updates for TCP SACK Panic vulnerabilities
description: Patch systems against the SACK Panic vulnerabilities that could expose
  servers to a denial of service attack with Canonical's Kernel Livepatch.
url: https://canonical.com/blog/mitigations-for-tcp-sack-panic-vulnerabilities?format=md
---

1. [Blog](https://canonical.com/blog)
2. Article

---

[Canonical](https://canonical.com/blog/author/canonical "More about Canonical")

5 July 2019

# Ubuntu updates for TCP SACK Panic vulnerabilities

[14.04](https://canonical.com/blog/tag/14-04)
[16.04](https://canonical.com/blog/tag/16-04)
[18.04](https://canonical.com/blog/tag/18-04)
[ESM](https://canonical.com/blog/tag/esm)
[Extended Security Maintenance](https://canonical.com/blog/tag/extended-security-maintenance)
[livepatch](https://canonical.com/blog/tag/livepatch)
[sack panic](https://canonical.com/blog/tag/sack-panic)
[Security](https://canonical.com/blog/tag/security)
[TCP Sack Panic](https://canonical.com/blog/tag/tcp-sack-panic)
[Trusty Tahr](https://canonical.com/blog/tag/trusty-tahr)

---

Share the article

Issues have been identified in the way the Linux kernel’s TCP implementation processes Selective Acknowledgement (SACK) options and handles low Maximum Segment Size (MSS) values. These TCP SACK Panic vulnerabilities could expose servers to a denial of service attack, so it is crucial to have systems patched.

Updated versions of the Linux kernel packages are being published as part of the standard Ubuntu security maintenance of Ubuntu releases 16.04 LTS, 18.04 LTS, 18.10, 19.04 and as part of the extended security maintenance for [Ubuntu 14.04 ESM](https://www.ubuntu.com/esm) users.

It is recommended to update to the latest kernel packages and consult [Ubuntu Security Notices](https://usn.ubuntu.com/) for further updates.

Ubuntu Advantage for Infrastructure subscription customers can find the latest status information in our [Knowledge Base](https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/SACKPanic) and [file a support case with Canonical support](https://support.canonical.com/ua/s/contactsupport) for any additional questions or concerns around SACK Panic.

[Canonical’s Kernel Livepatch](https://ubuntu.com/livepatch) updates for security vulnerabilities related to TCP SACK processing in the Linux kernel have been released and are described by CVEs [2019-11477](https://people.canonical.com/~ubuntu-security/cve/2019/CVE-2019-11477) and [2019-11478](https://people.canonical.com/~ubuntu-security/cve/2019/CVE-2019-11478), with details of the patch available in [LSN-0052-1](https://lists.ubuntu.com/archives/ubuntu-security-announce/2019-June/004962.html).

These CVEs have a Livepatch fix available, however, a minimum kernel version is required for Livepatch to install the fix as denoted by the table in [LSN-0052-1](https://lists.ubuntu.com/archives/ubuntu-security-announce/2019-June/004962.html), reproduced here:

```
| Kernel                   | Version | flavors           |
|--------------------------+----------+--------------------------|
| 4.4.0-148.174            | 52.3 | generic, lowlatency      |
| 4.4.0-150.176            | 52.3 | generic, lowlatency      |
| 4.15.0-50.54             | 52.3 | generic, lowlatency      |
| 4.15.0-50.54~16.04.1     | 52.3 | generic, lowlatency      |
| 4.15.0-51.55             | 52.3 | generic, lowlatency      |
| 4.15.0-51.55~16.04.1     | 52.3 | generic, lowlatency      |
```

Livepatch fixes for CVEs 2019-11477 and 2019-11478 are not available for prior kernels, and an upgrade and reboot to the appropriate minimum version is necessary. These kernel versions correspond to the availability of mitigations for the [MDS series](https://ubuntu.com/blog/ubuntu-updates-to-mitigate-new-microarchitectural-data-sampling-mds-vulnerabilities) of CVEs (CVE-2018-12126, CVE-2018-12127, CVE-2018-12130 and CVE-2019-11091).

Additionally, a third SACK related issue, [CVE-2019-11479](https://people.canonical.com/~ubuntu-security/cve/2019/CVE-2019-11479), does not have a Livepatch fix available because it is not technically feasible to apply the changes via Livepatch. Mitigation information is available at the [Ubuntu Security Team Wiki](https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/SACKPanic).

If you have any questions and want to learn more about these patches, please do not hesitate to [get in touch](https://ubuntu.com/security?utm_source=blog&utm_campaign=7013z000001dvfg#get-in-touch).

## Sign up for our newsletter

Get the latest Canonical news and updates in your inbox.

Work email:

\*I agree to receive information about Canonical's
products and services.

By submitting this form, I confirm that I have read and agree to [Canonical's Privacy Policy](https://canonical.com/legal/dataprivacy).

Sign up

## Share on

---

## Related posts

[### Canonical joins the Open Secure AI Alliance](https://canonical.com/blog/open-secure-ai-alliance)

Canonical is now part of the Open Secure AI Alliance, announced by NVIDIA with partners across cloud computing, cybersecurity, enterprise software, open source foundations, and...

[Canonical](https://canonical.com/blog/author/canonical)

28 August 2026

[### Januscape vulnerability CVE-2026-53359 mitigations available](https://canonical.com/blog/januscape-linux-vulnerability-mitigations-available)

Introduction A local privilege escalation (LPE) vulnerability affecting the Linux kernel was publicly disclosed on July 6, 2026. The vulnerability was assigned CVE ID...

[seth-arnold](https://canonical.com/blog/author/seth-arnold)

11 July 2026

[### DirtyClone Linux kernel local privilege escalation vulnerability fixes available](https://canonical.com/blog/dirtyclone-linux-vulnerability-fixes-available)

On June 25, 2026, JFrog published their research into CVE-2026-43503, referring to the vulnerability as DirtyClone. The vulnerability had previously been responsibly disclosed...

[Luci Stanescu](https://canonical.com/blog/author/lucistanescu)

1 July 2026

[### pedit COW kernel local privilege escalation vulnerability mitigations](https://canonical.com/blog/pedit-cow-linux-vulnerability-fixes-available)

Mitigations are available for the Linux vulnerability with CVE ID CVE-2026-46331. The CVE ID was assigned on June 16 2026 and highlighted as a local privilege escalation (LPE)...

[Luci Stanescu](https://canonical.com/blog/author/lucistanescu)

1 July 2026
