LinuxÄÚºËÖÐTCP SACKÔ¶³Ì»Ø¾ø·þÎñ·ì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2019-06-19·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-11478£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-11479£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
Ó°ÏìLinux ÄÚºË2.6.29¼°ÒÔÉϰ汾
·ì϶¸ÅÊö
SACKÊý¾Ý°üÄ£¿éÖз¢ÏÖÁËÈý¸ö·ì϶£¬CVE±àºÅΪCVE-2019-11477¡¢CVE-2019-11478ºÍCVE-2019-11479¡£
CVE-2019-11477 SACK Panic·ì϶ͨ¹ý¡°ÔÚÓµÓнÏÓ×ÖµµÄTCP MSSµÄTCPÏνÓÉÏ·¢Ë;«ÐÄÉè¼ÆµÄSACK¶ÎÐòÁÓ×±À´ÀûÓã¬Õâ»á´¥·¢ÕûÊýÒç³ö¡£¸Ã·ì϶¿ÉÄܽµµÍϵͳÔËÐÐЧÄÜ£¬²¢¿ÉÄܱ»Ô¶³Ì¹¥»÷ÕßÓÃÓڻؾø·þÎñ¹¥»÷£¬Ó°ÏìˮƽÑϳÁ¡£
CVE-2019-11478 SACK Slowness·ì϶ͨ¹ý·¢ËÍ¡°Ò»¸ö¾«ÐÄÉè¼ÆµÄSACKÐòÁÐÀ´·Ö»¯TCP³Á´«¶ÓÁÓ×±À´ÀûÓ㬶øCVE-2019-11479·ì϶ͨ¹ý·¢ËÍ¡°ÓµÓеÍMSSÖµµÄ¾«ÐÄÔì×÷µÄÊý¾Ý°ü¡±À´ÀûÓÃÔÊÐí¹¥»÷Õß´¥·¢DoS¡£
CVE-2019-5599ÊÇCVE-2019-11478µÄFreeBSD°æ±¾£¬ËüʹÓÃRACK TCP²Ö¿âÓ°ÏìFreeBSD 12µÄ×°Ö㬲¢ÇÒÄܹ»Í¨¹ýÌṩ¡°Ò»¸ö¾«ÐÄÉè¼ÆµÄSACKÐòÁÐÀ´·ÛËéRACK·¢ËÍÓ³É䡱¡£
¶ÔÎÒ¹ú¾³ÄÚʹÓÃLinux²Ù×÷ϵͳµÄ·þÎñÆ÷½øÐÐͳ¼Æ£¬Á˾ÖÏÔʾÎÒ¹ú¾³ÄÚÊ¢¿ª»¥ÁªÍø¶Ë¿ÚµÄLinux·þÎñÆ÷ÊýÁ¿Ô¼Îª202Íǫ̀¡£°´É¢²¼ÇøÍ³¼ÆÀ´¿´£¬ÅÅÃûǰÈýµÄÊ¡·ÝÊǹ㶫ʡ¡¢Õã½Ê¡ºÍ±±¾©ÊС£
·ì϶ÑéÖ¤
ÔÝÎÞPOC/EXP¡£
½¨¸´½¨Òé
£¨1£©ÊµÊ±¸üв¹¶¡£ºhttps://github.com/Netflix/security-bulletins/tree/master/advisories/third-party/2019-001¡£
£¨2£©½ûÓÃSACK´¦ÖÃecho 0 > /proc/sys/net/ipv4/tcp_sack
£¨3£©Ê¹ÓùýÂËÆ÷À´×èÖ¹¹¥»÷
https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-001/block-low-mss/README.md
´Ë»º½â±ØÒª½ûÓÃTCP̽²âʱÓÐЧ£¨¼´ÔÚ/etc/sysctl.confÎļþÖн«net.ipv4.tcp_mtu_probingsysctlÉèÖÃΪ0£©
£¨4£©RedHatÓû§Äܹ»Ê¹ÓÃÒÔϽÅÕý±¾²é³ÏµÍ³ÊÇ·ñ´æÔÚ·ì϶
https://access.redhat.com/sites/default/files/cve-2019-11477--2019-06-17-1629.sh
²Î¿¼Á´½Ó


¾©¹«Íø°²±¸11010802024551ºÅ