LinuxÄÚºËÖÐTCP SACKÔ¶³Ì»Ø¾ø·þÎñ·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-06-19

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-11477£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5£¬£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-11478£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-11479£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾

Ó°ÏìLinux ÄÚºË2.6.29¼°ÒÔÉϰ汾


·ì϶¸ÅÊö


2019Äê6ÔÂ18ÈÕ£¬£¬£¬£¬£¬£¬RedHat¹ÙÍø°ä²¼»ã±¨£º°²È«×êÑÐÈËÔ±ÔÚLinuxÄں˴¦ÖÃTCP

SACKÊý¾Ý°üÄ£¿£¿£¿£¿£¿£¿éÖз¢ÏÖÁËÈý¸ö·ì϶£¬£¬£¬£¬£¬£¬CVE±àºÅΪCVE-2019-11477¡¢CVE-2019-11478ºÍCVE-2019-11479¡£¡£ ¡£¡£¡£¡£¡£


CVE-2019-11477 SACK Panic·ì϶ͨ¹ý¡°ÔÚÓµÓнÏÓ×ÖµµÄTCP MSSµÄTCPÏνÓÉÏ·¢Ë;«ÐÄÉè¼ÆµÄSACK¶ÎÐòÁÓ×±À´ÀûÓ㬣¬£¬£¬£¬£¬Õâ»á´¥·¢ÕûÊýÒç³ö¡£¡£ ¡£¡£¡£¡£¡£¸Ã·ì϶¿ÉÄܽµµÍϵͳÔËÐÐЧÄÜ£¬£¬£¬£¬£¬£¬²¢¿ÉÄܱ»Ô¶³Ì¹¥»÷ÕßÓÃÓڻؾø·þÎñ¹¥»÷£¬£¬£¬£¬£¬£¬Ó°ÏìˮƽÑϳÁ¡£¡£ ¡£¡£¡£¡£¡£


CVE-2019-11478 SACK Slowness·ì϶ͨ¹ý·¢ËÍ¡°Ò»¸ö¾«ÐÄÉè¼ÆµÄSACKÐòÁÐÀ´·Ö»¯TCP³Á´«¶ÓÁÓ×±À´ÀûÓ㬣¬£¬£¬£¬£¬¶øCVE-2019-11479·ì϶ͨ¹ý·¢ËÍ¡°ÓµÓеÍMSSÖµµÄ¾«ÐÄÔì×÷µÄÊý¾Ý°ü¡±À´ÀûÓÃÔÊÐí¹¥»÷Õß´¥·¢DoS¡£¡£ ¡£¡£¡£¡£¡£


CVE-2019-5599ÊÇCVE-2019-11478µÄFreeBSD°æ±¾£¬£¬£¬£¬£¬£¬ËüʹÓÃRACK TCP²Ö¿âÓ°ÏìFreeBSD 12µÄ×°Ö㬣¬£¬£¬£¬£¬²¢ÇÒÄܹ»Í¨¹ýÌṩ¡°Ò»¸ö¾«ÐÄÉè¼ÆµÄSACKÐòÁÐÀ´·ÛËéRACK·¢ËÍÓ³É䡱¡£¡£ ¡£¡£¡£¡£¡£


¶ÔÎÒ¹ú¾³ÄÚʹÓÃLinux²Ù×÷ϵͳµÄ·þÎñÆ÷½øÐÐͳ¼Æ£¬£¬£¬£¬£¬£¬Á˾ÖÏÔʾÎÒ¹ú¾³ÄÚÊ¢¿ª»¥ÁªÍø¶Ë¿ÚµÄLinux·þÎñÆ÷ÊýÁ¿Ô¼Îª202Íǫ̀¡£¡£ ¡£¡£¡£¡£¡£°´É¢²¼ÇøÍ³¼ÆÀ´¿´£¬£¬£¬£¬£¬£¬ÅÅÃûǰÈýµÄÊ¡·ÝÊǹ㶫ʡ¡¢Õã½­Ê¡ºÍ±±¾©ÊС£¡£ ¡£¡£¡£¡£¡£


·ì϶ÑéÖ¤


ÔÝÎÞPOC/EXP¡£¡£ ¡£¡£¡£¡£¡£


½¨¸´½¨Òé


£¨1£©ÊµÊ±¸üв¹¶¡£¡£ ¡£¡£¡£¡£¡£ºhttps://github.com/Netflix/security-bulletins/tree/master/advisories/third-party/2019-001¡£¡£ ¡£¡£¡£¡£¡£

£¨2£©½ûÓÃSACK´¦ÖÃ
echo 0 > /proc/sys/net/ipv4/tcp_sack
£¨3£©Ê¹ÓùýÂËÆ÷À´×èÖ¹¹¥»÷
https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-001/block-low-mss/README.md
´Ë»º½â±ØÒª½ûÓÃTCP̽²âʱÓÐЧ£¨¼´ÔÚ/etc/sysctl.confÎļþÖн«net.ipv4.tcp_mtu_probingsysctlÉèÖÃΪ0£©
£¨4£©RedHatÓû§Äܹ»Ê¹ÓÃÒÔϽÅÕý±¾²é³­ÏµÍ³ÊÇ·ñ´æÔÚ·ì϶

https://access.redhat.com/sites/default/files/cve-2019-11477--2019-06-17-1629.sh


²Î¿¼Á´½Ó


https://access.redhat.com/security/vulnerabilities/tcpsack