{"id":35396,"date":"2019-10-31T22:04:04","date_gmt":"2019-10-31T19:04:04","guid":{"rendered":"https:\/\/prohoster.info\/blog\/uyazvimosti-v-tcp-stekah-linux-i-freebsd-privodyashhie-k-udalyonnomu-otkazu-v-obsluzhivanii\/"},"modified":"2019-10-31T22:04:04","modified_gmt":"2019-10-31T19:04:04","slug":"uyazvimosti-v-tcp-stekah-linux-i-freebsd-privodyashhie-k-udalyonnomu-otkazu-v-obsluzhivanii","status":"publish","type":"post","link":"https:\/\/prohoster.info\/sq\/blog\/news\/uyazvimosti-v-tcp-stekah-linux-i-freebsd-privodyashhie-k-udalyonnomu-otkazu-v-obsluzhivanii","title":{"rendered":"Vulnerabilitetet n\u00eb stacket TCP t\u00eb Linux dhe FreeBSD q\u00eb \u00e7ojn\u00eb n\u00eb nj\u00eb refus t\u00eb sh\u00ebrbimit n\u00eb distanc\u00eb.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Kompanis\u00eb Netflix <noindex><a rel=\"nofollow\" href=\"https:\/\/www.openwall.com\/lists\/oss-security\/2019\/06\/17\/5\">identifikoi<\/a><\/noindex> disa kritike <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/Netflix\/security-bulletins\/blob\/master\/advisories\/third-party\/2019-001.md\">dob\u00ebsive<\/a><\/noindex> n\u00eb stek\u00ebt TCP t\u00eb Linux dhe FreeBSD, t\u00eb cilat lejojn\u00eb q\u00eb nga distanca t\u00eb inicohet nj\u00eb shkelje e b\u00ebrtham\u00ebs ose t\u00eb shkaktohet konsumim i tepruar i burimeve gjat\u00eb p\u00ebrpunimit t\u00eb paketave TCP t\u00eb krijuara n\u00eb m\u00ebnyr\u00eb speciale (packet-of-death). Problemet <noindex><a rel=\"nofollow\" href=\"https:\/\/access.redhat.com\/security\/vulnerabilities\/tcpsack\">kan\u00eb shkaktuar<\/a><\/noindex> gabime n\u00eb trajtuesit e madh\u00ebsis\u00eb maksimale t\u00eb bllokut t\u00eb t\u00eb dh\u00ebnave n\u00eb paket\u00ebn TCP (MSS, Maximum segment size) dhe mekanizmin e konfirmimit selektiv t\u00eb lidhjeve (SACK, TCP Selective Acknowledgement).<\/p>\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2019-11477\">CVE-2019-11477<\/a><\/noindex> (SACK Panic) \u2014 problemi shfaqet n\u00eb b\u00ebrthamat Linux q\u00eb nga versioni 2.6.29 dhe lejon shkaktimin e nj\u00eb kolapsi (panic) t\u00eb b\u00ebrtham\u00ebs p\u00ebrmes d\u00ebrgimit t\u00eb nj\u00eb s\u00ebr\u00eb paketash SACK p\u00ebr shkak t\u00eb osh\u00ebllimit t\u00eb numrave n\u00eb procesorin. P\u00ebr t\u00eb realizuar sulmin, \u00ebsht\u00eb e mjaftueshme q\u00eb t\u00eb vendoset nj\u00eb vler\u00eb MSS prej 48 byte p\u00ebr lidhjen TCP (limiti i posht\u00ebm, i cili vendos p\u00ebrmas\u00ebn e segmentit n\u00eb 8 byte) dhe t\u00eb d\u00ebrgohen nj\u00eb s\u00ebr\u00eb paketash SACK t\u00eb organizuara n\u00eb nj\u00eb m\u00ebnyr\u00eb specifike.\n<p>Si masa mbrojt\u00ebse, mund t\u00eb \u00e7aktivizohet p\u00ebrpunimi i SACK (t\u00eb shkruani 0 n\u00eb \/proc\/sys\/net\/ipv4\/tcp_sack) ose <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/Netflix\/security-bulletins\/blob\/master\/advisories\/third-party\/2019-001\/block-low-mss\/README.md\">t\u00eb blokoni<\/a><\/noindex> lidhjet me MSS t\u00eb ul\u00ebt (funksionon vet\u00ebm kur vendoset sysctl net.ipv4.tcp_mtu_probing n\u00eb 0 dhe mund t\u00eb d\u00ebmtoj\u00eb funksionimin e disa lidhjeve normale me MSS t\u00eb ul\u00ebt);<\/p>\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2019-11478\">CVE-2019-11478<\/a><\/noindex> (SACK Slowness) \u2014 \u00e7on n\u00eb nd\u00ebrprerje t\u00eb funksionit t\u00eb mekanizmit SACK (kur p\u00ebrdoret b\u00ebrthama Linux m\u00eb t\u00eb ul\u00ebt se 4.15) ose konsum t\u00eb tepruar burimesh. Problemi shfaqet gjat\u00eb p\u00ebrpunimit t\u00eb paketave SACK t\u00eb dizajnuara posa\u00e7\u00ebrisht, t\u00eb cilat mund t\u00eb p\u00ebrdoren p\u00ebr fragmentimin e radh\u00ebs s\u00eb p\u00ebrs\u00ebritjes (TCP retransmission). Rrug\u00ebt e mbrojtjes jan\u00eb t\u00eb ngjashme me ato t\u00eb shkeljes s\u00eb m\u00ebparshme;\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2019-5599\">CVE-2019-5599<\/a><\/noindex> (SACK Slowness) \u2014 lejon shkaktimin e fragmentimin t\u00eb hart\u00ebs s\u00eb paketave t\u00eb d\u00ebrguara gjat\u00eb p\u00ebrpunimit t\u00eb nj\u00eb sekuence speciale SACK brenda nj\u00eb lidhjeje TCP dhe shkaktimin e realizimit t\u00eb nj\u00eb operacioni ngarkues t\u00eb shfletimit t\u00eb list\u00ebs. Problemi shfaqet n\u00eb FreeBSD 12 me mekanizmin e identifikimit t\u00eb humbjes s\u00eb paketave RACK. Si mas\u00eb mbrojt\u00ebse, mund t\u00eb \u00e7aktivizohet moduli RACK;\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2019-11478\">CVE-2019-11479<\/a><\/noindex> \u2014 sulmuesi mund t\u00eb shkaktoj\u00eb ndarjen e p\u00ebrgjigjeve n\u00eb disa segmente TCP n\u00eb b\u00ebrtham\u00ebn Linux, secili prej t\u00eb cil\u00ebve p\u00ebrmban vet\u00ebm 8 byte t\u00eb dh\u00ebnave, \u00e7ka mund t\u00eb sjell\u00eb nj\u00eb rritje t\u00eb konsiderueshme t\u00eb trafikut, rritje n\u00eb ngarkes\u00ebn e CPU-s\u00eb dhe ngopjen e kanalit t\u00eb komunikimit. Si nj\u00eb metod\u00eb mbrojt\u00ebse rekomandohet <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/Netflix\/security-bulletins\/blob\/master\/advisories\/third-party\/2019-001\/block-low-mss\/README.md\">t\u00eb blokoni<\/a><\/noindex> lidhjet me MSS t\u00eb ul\u00ebt.\n<\/ul>\n<p>N\u00eb b\u00ebrtham\u00ebn Linux, problemet jan\u00eb zgjidhur n\u00eb l\u00ebshimet 4.4.182, 4.9.182, 4.14.127, 4.19.52 dhe 5.1.11. Nj\u00eb korrigjim p\u00ebr FreeBSD \u00ebsht\u00eb n\u00eb dispozicion n\u00eb form\u00eb <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/Netflix\/security-bulletins\/blob\/master\/advisories\/third-party\/2019-001\/split_limit.patch\">patch-it<\/a><\/noindex>. N\u00eb shp\u00ebrndarjet, p\u00ebrdit\u00ebsimet e pakove me b\u00ebrtham\u00eb tashm\u00eb jan\u00eb l\u00ebshuar p\u00ebr <noindex><a rel=\"nofollow\" href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2019-11477\">Debian<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=CVE-2019-11477\">RHEL<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/www.suse.com\/security\/cve\/CVE-2019-11477\/\">SUSE\/openSUSE<\/a><\/noindex>. Nj\u00eb korrigjim \u00ebsht\u00eb n\u00eb proces p\u00ebr <noindex><a rel=\"nofollow\" href=\"https:\/\/people.canonical.com\/~ubuntu-security\/cve\/2019\/CVE-2019-11477.html\">Ubuntu<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/bodhi.fedoraproject.org\/updates\/?releases=F30&#038;type=security\">Fedora<\/a><\/noindex> dhe <noindex><a rel=\"nofollow\" href=\"https:\/\/security.archlinux.org\/\">Arch Linux<\/a><\/noindex>.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Burimi: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=50889\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f Netflix \u0432\u044b\u044f\u0432\u0438\u043b\u0430 \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0438\u0445 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0432 TCP-\u0441\u0442\u0435\u043a\u0430\u0445 Linux \u0438 FreeBSD, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0442 \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u0438\u043d\u0438\u0446\u0438\u0438\u0440\u043e\u0432\u0430\u0442\u044c \u043a\u0440\u0430\u0445 \u044f\u0434\u0440\u0430 \u0438\u043b\u0438 \u0432\u044b\u0437\u0432\u0430\u0442\u044c \u0447\u0440\u0435\u0437\u043c\u0435\u0440\u043d\u043e\u0435 \u043f\u043e\u0442\u0440\u0435\u0431\u043b\u0435\u043d\u0438\u0435 \u0440\u0435\u0441\u0443\u0440\u0441\u043e\u0432 \u043f\u0440\u0438 \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0435 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043e\u0444\u043e\u0440\u043c\u043b\u0435\u043d\u043d\u044b\u0445 TCP-\u043f\u0430\u043a\u0435\u0442\u043e\u0432 (packet-of-death). \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u044b \u0432\u044b\u0437\u0432\u0430\u043d\u044b \u043e\u0448\u0438\u0431\u043a\u0430\u043c\u0438 \u0432 \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0430\u0445 \u043c\u0430\u043a\u0441\u0438\u043c\u0430\u043b\u044c\u043d\u043e\u0433\u043e \u0440\u0430\u0437\u043c\u0435\u0440\u0430 \u0431\u043b\u043e\u043a\u0430 \u0434\u0430\u043d\u043d\u044b\u0445 \u0432 TCP-\u043f\u0430\u043a\u0435\u0442\u0435 (MSS, Maximum segment size) \u0438 \u043c\u0435\u0445\u0430\u043d\u0438\u0437\u043c\u0430 \u0432\u044b\u0431\u043e\u0440\u043e\u0447\u043d\u043e\u0433\u043e \u043f\u043e\u0434\u0442\u0432\u0435\u0440\u0436\u0434\u0435\u043d\u0438\u044f \u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u0439 (SACK, TCP Selective Acknowledgement). CVE-2019-11477 (SACK Panic) [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-35396","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f Netflix \u0432\u044b\u044f\u0432\u0438\u043b\u0430 \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0438\u0445\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/sq\/blog\/news\/uyazvimosti-v-tcp-stekah-linux-i-freebsd-privodyashhie-k-udalyonnomu-otkazu-v-obsluzhivanii\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"sq_AL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 TCP-\u0441\u0442\u0435\u043a\u0430\u0445 Linux \u0438 FreeBSD, \u043f\u0440\u0438\u0432\u043e\u0434\u044f\u0449\u0438\u0435 \u043a \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e\u043c\u0443 \u043e\u0442\u043a\u0430\u0437\u0443 \u0432 \u043e\u0431\u0441\u043b\u0443\u0436\u0438\u0432\u0430\u043d\u0438\u0438 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f Netflix \u0432\u044b\u044f\u0432\u0438\u043b\u0430 \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0438\u0445\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/sq\/blog\/news\/uyazvimosti-v-tcp-stekah-linux-i-freebsd-privodyashhie-k-udalyonnomu-otkazu-v-obsluzhivanii\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T19:04:04+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T19:04:04+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vulnerabilitetet n\u00eb stak\u00ebt TCP t\u00eb Linux dhe FreeBSD, q\u00eb \u00e7ojn\u00eb n\u00eb nj\u00eb sh\u00ebrbim t\u00eb \u00e7aktivizuar n\u00eb distanc\u00eb | ProHoster","description":"Kompania Netflix ka identifikuar disa vulnerabilitete kritike","canonical_url":"https:\/\/prohoster.info\/sq\/blog\/news\/uyazvimosti-v-tcp-stekah-linux-i-freebsd-privodyashhie-k-udalyonnomu-otkazu-v-obsluzhivanii","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"sq_AL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 TCP-\u0441\u0442\u0435\u043a\u0430\u0445 Linux \u0438 FreeBSD, \u043f\u0440\u0438\u0432\u043e\u0434\u044f\u0449\u0438\u0435 \u043a \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e\u043c\u0443 \u043e\u0442\u043a\u0430\u0437\u0443 \u0432 \u043e\u0431\u0441\u043b\u0443\u0436\u0438\u0432\u0430\u043d\u0438\u0438 | ProHoster","og:description":"\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f Netflix \u0432\u044b\u044f\u0432\u0438\u043b\u0430 \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0438\u0445","og:url":"https:\/\/prohoster.info\/sq\/blog\/news\/uyazvimosti-v-tcp-stekah-linux-i-freebsd-privodyashhie-k-udalyonnomu-otkazu-v-obsluzhivanii","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T19:04:04+00:00","article:modified_time":"2019-10-31T19:04:04+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"35396","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-21 23:03:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 17:03:04","updated":"2026-01-21 23:03:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/35396","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/comments?post=35396"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/35396\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media?parent=35396"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/categories?post=35396"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/tags?post=35396"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}