TCP SACK Panic — Kernel vulnerabilities leading to remote denial of service

Netflix employees found three vulnerabilities in the TCP network stack code. The most severe of these vulnerabilities allows a remote attacker to trigger a kernel panic.

Several CVE identifiers were assigned to these issues: CVE-2019-11477 classified as a critical vulnerability, along with CVE-2019-11478 and CVE-2019-11479 as moderate.

The first two vulnerabilities relate to SACK (Selective Acknowledgement) and MSS (Maximum Segment Size). The third one only pertains to MSS.

Source: linux.org.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster