CVE-2019-5599
Estado: ModificadaAlta (7.5)—
In FreeBSD 12.0-STABLE before r349197 and 12.0-RELEASE before 12.0-RELEASE-p6, a bug in the non-default RACK TCP stack can allow an attacker to cause several linked lists to grow unbounded and cause an expensive list traversal on every packet being processed, leading to resource exhaustion and a denial of service.
CVSS
- Versión: 3.0
- Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 5.08%
- Percentil entre todas las CVEs puntuadas: 92
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-770
Referencias
- http://packetstormsecurity.com/files/153329/Linux-FreeBSD-TCP-Based-Denial-Of-Service.html
- http://packetstormsecurity.com/files/153378/FreeBSD-Security-Advisory-FreeBSD-SA-19-08.rack.html
- http://www.openwall.com/lists/oss-security/2019/06/17/5
- https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-001.md
- https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44193
- https://seclists.org/bugtraq/2019/Jun/27
- https://security.FreeBSD.org/advisories/FreeBSD-SA-19:08.rack.asc
- https://security.netapp.com/advisory/ntap-20190625-0004/
- https://support.f5.com/csp/article/K75521003
- https://www.kb.cert.org/vuls/id/905115
- http://packetstormsecurity.com/files/153329/Linux-FreeBSD-TCP-Based-Denial-Of-Service.html
- http://packetstormsecurity.com/files/153378/FreeBSD-Security-Advisory-FreeBSD-SA-19-08.rack.html
- http://www.openwall.com/lists/oss-security/2019/06/17/5
- https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-001.md
- https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44193
- https://seclists.org/bugtraq/2019/Jun/27
- https://security.FreeBSD.org/advisories/FreeBSD-SA-19:08.rack.asc
- https://security.netapp.com/advisory/ntap-20190625-0004/
- https://support.f5.com/csp/article/K75521003
- https://www.kb.cert.org/vuls/id/905115
JSON original (NVD)
Mostrar
{
"id": "CVE-2019-5599",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.8,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:C",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 6.9,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "secteam@freebsd.org",
"affectedData": [
{
"vendor": "n/a",
"product": "FreeBSD",
"versions": [
{
"status": "affected",
"version": "FreeBSD 12.0 before 12.0-RELEASE-p6"
}
]
}
]
}
],
"published": "2019-07-02T21:15:11.213",
"references": [
{
"url": "http://packetstormsecurity.com/files/153329/Linux-FreeBSD-TCP-Based-Denial-Of-Service.html",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "secteam@freebsd.org"
},
{
"url": "http://packetstormsecurity.com/files/153378/FreeBSD-Security-Advisory-FreeBSD-SA-19-08.rack.html",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "secteam@freebsd.org"
},
{
"url": "http://www.openwall.com/lists/oss-security/2019/06/17/5",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "secteam@freebsd.org"
},
{
"url": "https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-001.md",
"tags": [
"Mitigation",
"Third Party Advisory"
],
"source": "secteam@freebsd.org"
},
{
"url": "https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44193",
"tags": [
"Third Party Advisory"
],
"source": "secteam@freebsd.org"
},
{
"url": "https://seclists.org/bugtraq/2019/Jun/27",
"tags": [
"Mailing List",
"Mitigation",
"Patch",
"Third Party Advisory"
],
"source": "secteam@freebsd.org"
},
{
"url": "https://security.FreeBSD.org/advisories/FreeBSD-SA-19:08.rack.asc",
"tags": [
"Mitigation",
"Vendor Advisory"
],
"source": "secteam@freebsd.org"
},
{
"url": "https://security.netapp.com/advisory/ntap-20190625-0004/",
"tags": [
"Third Party Advisory"
],
"source": "secteam@freebsd.org"
},
{
"url": "https://support.f5.com/csp/article/K75521003",
"tags": [
"Third Party Advisory"
],
"source": "secteam@freebsd.org"
},
{
"url": "https://www.kb.cert.org/vuls/id/905115",
"tags": [
"Third Party Advisory",
"US Government Resource"
],
"source": "secteam@freebsd.org"
},
{
"url": "http://packetstormsecurity.com/files/153329/Linux-FreeBSD-TCP-Based-Denial-Of-Service.html",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://packetstormsecurity.com/files/153378/FreeBSD-Security-Advisory-FreeBSD-SA-19-08.rack.html",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.openwall.com/lists/oss-security/2019/06/17/5",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-001.md",
"tags": [
"Mitigation",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44193",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://seclists.org/bugtraq/2019/Jun/27",
"tags": [
"Mailing List",
"Mitigation",
"Patch",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://security.FreeBSD.org/advisories/FreeBSD-SA-19:08.rack.asc",
"tags": [
"Mitigation",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://security.netapp.com/advisory/ntap-20190625-0004/",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://support.f5.com/csp/article/K75521003",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.kb.cert.org/vuls/id/905115",
"tags": [
"Third Party Advisory",
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-770"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In FreeBSD 12.0-STABLE before r349197 and 12.0-RELEASE before 12.0-RELEASE-p6, a bug in the non-default RACK TCP stack can allow an attacker to cause several linked lists to grow unbounded and cause an expensive list traversal on every packet being processed, leading to resource exhaustion and a denial of service."
},
{
"lang": "es",
"value": "En FreeBSD versión 12.0-STABLE anterior a r349197 y versión 12.0-RELEASE anterior a 12.0-RELEASE-p6, un bug en la pila de RACK TCP no predeterminada puede permitir a un atacante causar que varias listas vinculadas crezcan sin límites y causar un salto de lista costoso en cada paquete procesado, lo que conlleva al agotamiento de los recursos y una denegación de servicio."
}
],
"lastModified": "2026-06-17T02:37:55.047",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:freebsd:freebsd:12.0:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "826B53C2-517F-4FC6-92E8-E7FCB24F91B4"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:12.0:p1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "93F10A46-AEF2-4FDD-92D6-0CF07B70F986"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:12.0:p2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E1AD57A9-F53A-4E40-966E-F2F50852C5E4"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:12.0:p3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C4029113-130F-4A33-A8A0-BC3E74000378"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:12.0:p4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "46C5A6FD-7BBF-4E84-9895-8EE14DC846E4"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:12.0:p5:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6D71D083-3279-4DF4-91E1-38C373DD062F"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "secteam@freebsd.org"
}