LinuxÄÚºËÖÐTCP SACKÔ¶³Ì»Ø¾ø·þÎñ·ì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2019-06-19·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-11478£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-11479£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
Ó°ÏìLinux ÄÚºË2.6.29¼°ÒÔÉϰ汾
·ì϶¸ÅÊö
SACKÊý¾Ý°üÄ£¿£¿£¿£¿£¿£¿éÖз¢ÏÖÁËÈý¸ö·ì϶£¬£¬£¬£¬£¬£¬CVE±àºÅΪCVE-2019-11477¡¢CVE-2019-11478ºÍCVE-2019-11479¡£¡£¡£¡£¡£¡£¡£
CVE-2019-11477 SACK Panic·ì϶ͨ¹ý¡°ÔÚÓµÓнÏÓ×ÖµµÄTCP MSSµÄTCPÏνÓÉÏ·¢Ë;«ÐÄÉè¼ÆµÄSACK¶ÎÐòÁÓ×±À´ÀûÓ㬣¬£¬£¬£¬£¬Õâ»á´¥·¢ÕûÊýÒç³ö¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶¿ÉÄܽµµÍϵͳÔËÐÐЧÄÜ£¬£¬£¬£¬£¬£¬²¢¿ÉÄܱ»Ô¶³Ì¹¥»÷ÕßÓÃÓڻؾø·þÎñ¹¥»÷£¬£¬£¬£¬£¬£¬Ó°ÏìˮƽÑϳÁ¡£¡£¡£¡£¡£¡£¡£
CVE-2019-11478 SACK Slowness·ì϶ͨ¹ý·¢ËÍ¡°Ò»¸ö¾«ÐÄÉè¼ÆµÄSACKÐòÁÐÀ´·Ö»¯TCP³Á´«¶ÓÁÓ×±À´ÀûÓ㬣¬£¬£¬£¬£¬¶øCVE-2019-11479·ì϶ͨ¹ý·¢ËÍ¡°ÓµÓеÍMSSÖµµÄ¾«ÐÄÔì×÷µÄÊý¾Ý°ü¡±À´ÀûÓÃÔÊÐí¹¥»÷Õß´¥·¢DoS¡£¡£¡£¡£¡£¡£¡£
CVE-2019-5599ÊÇCVE-2019-11478µÄFreeBSD°æ±¾£¬£¬£¬£¬£¬£¬ËüʹÓÃRACK TCP²Ö¿âÓ°ÏìFreeBSD 12µÄ×°Ö㬣¬£¬£¬£¬£¬²¢ÇÒÄܹ»Í¨¹ýÌṩ¡°Ò»¸ö¾«ÐÄÉè¼ÆµÄSACKÐòÁÐÀ´·ÛËéRACK·¢ËÍÓ³É䡱¡£¡£¡£¡£¡£¡£¡£
¶ÔÎÒ¹ú¾³ÄÚʹÓÃLinux²Ù×÷ϵͳµÄ·þÎñÆ÷½øÐÐͳ¼Æ£¬£¬£¬£¬£¬£¬Á˾ÖÏÔʾÎÒ¹ú¾³ÄÚÊ¢¿ª»¥ÁªÍø¶Ë¿ÚµÄLinux·þÎñÆ÷ÊýÁ¿Ô¼Îª202Íǫ̀¡£¡£¡£¡£¡£¡£¡£°´É¢²¼ÇøÍ³¼ÆÀ´¿´£¬£¬£¬£¬£¬£¬ÅÅÃûǰÈýµÄÊ¡·ÝÊǹ㶫ʡ¡¢Õã½Ê¡ºÍ±±¾©ÊС£¡£¡£¡£¡£¡£¡£
·ì϶ÑéÖ¤
ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£¡£¡£
½¨¸´½¨Òé
£¨1£©ÊµÊ±¸üв¹¶¡£¡£¡£¡£¡£¡£¡£ºhttps://github.com/Netflix/security-bulletins/tree/master/advisories/third-party/2019-001¡£¡£¡£¡£¡£¡£¡£
£¨2£©½ûÓÃSACK´¦ÖÃecho 0 > /proc/sys/net/ipv4/tcp_sack
£¨3£©Ê¹ÓùýÂËÆ÷À´×èÖ¹¹¥»÷
https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-001/block-low-mss/README.md
´Ë»º½â±ØÒª½ûÓÃTCP̽²âʱÓÐЧ£¨¼´ÔÚ/etc/sysctl.confÎļþÖн«net.ipv4.tcp_mtu_probingsysctlÉèÖÃΪ0£©
£¨4£©RedHatÓû§Äܹ»Ê¹ÓÃÒÔϽÅÕý±¾²é³ÏµÍ³ÊÇ·ñ´æÔÚ·ì϶
https://access.redhat.com/sites/default/files/cve-2019-11477--2019-06-17-1629.sh
²Î¿¼Á´½Ó


¾©¹«Íø°²±¸11010802024551ºÅ