# CVE-2019-8460

## Summary

- **CVE ID:** CVE-2019-8460
- **Severity:** UNKNOWN
- **CVSS Score:** 0.03
- **CWE:** CWE-1049
- **Published:** Aug 26, 2019
- **Last Modified:** Mar 14, 2026

## Description

OpenBSD kernel version <= 6.5 can be forced to create long chains of TCP SACK holes that causes very expensive calls to tcp_sack_option() for every incoming SACK packet which can lead to a denial of service.

## Affected Products

- n/a — OpenBSD (All, including latest - 6.5)

## References

- [CNA](https://github.com/openbsd/src/commit/ed8fdce754a5d8d14c09e989d8877707bd43906f)
- [CNA](https://ftp.openbsd.org/pub/OpenBSD/patches/6.5/common/006_tcpsack.patch.sig)
- [CNA](https://security.netapp.com/advisory/ntap-20190905-0001/)
- [CNA](https://research.checkpoint.com/tcp-sack-security-issue-in-openbsd-cve-2019-8460/)
- [CNA](https://us-cert.cisa.gov/ics/advisories/icsa-19-253-03)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.69%
- **EPSS Percentile:** 71.4

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-12._