TCP SACK Panic — Vulnerabilità del kernel che portano a un attacco Denial of Service remoto

I dipendenti di Netflix hanno scoperto tre vulnerabilità nel codice dello stack di rete per TCP. La vulnerabilità più grave consente a un attaccante remoto di causare un panic del kernel.

Alle problematiche sono stati associati diversi identificatori CVE: CVE-2019-11477 è stata classificata come vulnerabilità significativa, mentre CVE-2019-11478 e CVE-2019-11479 sono considerate moderate.

Le prime due vulnerabilità riguardano il SACK (Selective Acknowledgement) e il MSS (Maximum Segment Size). La terza riguarda solo il MSS.

Fonte: linux.org.ru

Acquista un hosting affidabile per siti web con protezione DDoS, VPS VDS server 🔥 Acquista un hosting affidabile per siti web con protezione DDoS, VPS VDS server | ProHoster