CVE-2019-11683: Critical severity Linux Linux kernel vulnerability
Last updated 4 July 2026
Other sources
udpgroreceivesegment in net/ipv4/udpoffload.c in the Linux kernel 5.x before 5.0.13 allows remote attackers to cause a denial of service (slab-out-of-bounds memory corruption) or possibly have unspecified other impact via UDP packets with a 0 payload, because of mishandling of padded packets, aka the "GRO packet of death" issue.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.176-1Fixed in 6.1.187-1Fixed in 6.12.94-1Fixed in 6.12.107-1Fixed in 7.1.12-1Fixed in 7.1.13-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 5.0.13
Event History
Frequently Asked Questions
What is the vulnerability ID for this Linux kernel vulnerability?
The vulnerability ID for this Linux kernel vulnerability is CVE-2019-11683.
How does the vulnerability CVE-2019-11683 impact the Linux kernel 5.x before 5.0.13?
The vulnerability CVE-2019-11683 allows remote attackers to cause a denial of service (slab-out-of-bounds memory corruption) or possibly have unspecified other impact via UDP packets with a 0 payload, because of mishandling of padded packets.
What software versions are affected by vulnerability CVE-2019-11683?
The Linux kernel 5.x before 5.0.13 is affected by vulnerability CVE-2019-11683.
How can I fix vulnerability CVE-2019-11683 in the Linux kernel 5.x before 5.0.13?
To fix vulnerability CVE-2019-11683, update the Linux kernel to version 5.0.13 or higher.
Where can I find more information about vulnerability CVE-2019-11683?
You can find more information about vulnerability CVE-2019-11683 on the following websites: [SecurityFocus](http://www.securityfocus.com/bid/108142), [Linux Kernel ChangeLog](https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.0.13), [NetApp Security Advisory](https://security.netapp.com/advisory/ntap-20190517-0002/)