LinuxÄÚºËÖÐTCP SACKÔ¶³Ì¾Ü¾øÐ§ÀÍÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-06-19Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-11478£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-11479£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
Ó°ÏìLinux ÄÚºË2.6.29¼°ÒÔÉϰ汾
Îó²î¸ÅÊö
SACKÊý¾Ý°üÄ£¿£¿£¿£¿£¿£¿éÖз¢Ã÷ÁËÈý¸öÎó²î£¬£¬£¬£¬CVE±àºÅΪCVE-2019-11477¡¢CVE-2019-11478ºÍCVE-2019-11479¡£¡£¡£¡£¡£¡£¡£
CVE-2019-11477 SACK PanicÎó²îͨ¹ý¡°ÔÚ¾ßÓнÏСֵµÄTCP MSSµÄTCPÅþÁ¬ÉÏ·¢ËÍÈ«ÐÄÉè¼ÆµÄSACK¶ÎÐòÁС±À´Ê¹Ó㬣¬£¬£¬Õâ»á´¥·¢ÕûÊýÒç³ö¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îÄܹ»½µµÍϵͳÔËÐÐЧÂÊ£¬£¬£¬£¬²¢¿ÉÄܱ»Ô¶³Ì¹¥»÷ÕßÓÃÓھܾøÐ§À͹¥»÷£¬£¬£¬£¬Ó°ÏìˮƽÑÏÖØ¡£¡£¡£¡£¡£¡£¡£
CVE-2019-11478 SACK SlownessÎó²îͨ¹ý·¢ËÍ¡°Ò»¸öÈ«ÐÄÉè¼ÆµÄSACKÐòÁÐÀ´ÆÊÎöTCPÖØ´«ÐÐÁС±À´Ê¹Ó㬣¬£¬£¬¶øCVE-2019-11479Îó²îͨ¹ý·¢ËÍ¡°¾ßÓеÍMSSÖµµÄÈ«ÐÄÖÆ×÷µÄÊý¾Ý°ü¡±À´Ê¹ÓÃÔÊÐí¹¥»÷Õß´¥·¢DoS¡£¡£¡£¡£¡£¡£¡£
CVE-2019-5599ÊÇCVE-2019-11478µÄFreeBSD°æ±¾£¬£¬£¬£¬ËüʹÓÃRACK TCP¿ÍÕ»Ó°ÏìFreeBSD 12µÄ×°Ö㬣¬£¬£¬²¢ÇÒ¿ÉÒÔͨ¹ýÌṩ¡°Ò»¸öÈ«ÐÄÉè¼ÆµÄSACKÐòÁÐÀ´ÆÆËðRACK·¢ËÍÓ³É䡱¡£¡£¡£¡£¡£¡£¡£
¶ÔÎÒ¹ú¾³ÄÚʹÓÃLinux²Ù×÷ϵͳµÄЧÀÍÆ÷¾ÙÐÐͳ¼Æ£¬£¬£¬£¬Ð§¹ûÏÔʾÎÒ¹ú¾³ÄÚ¿ª·Å»¥ÁªÍø¶Ë¿ÚµÄLinuxЧÀÍÆ÷ÊýĿԼΪ202Íǫ̀¡£¡£¡£¡£¡£¡£¡£°´ÂþÑÜÇøÍ³¼ÆÀ´¿´£¬£¬£¬£¬ÅÅÃûǰÈýµÄÊ¡·ÝÊǹ㶫ʡ¡¢Õã½Ê¡ºÍ±±¾©ÊС£¡£¡£¡£¡£¡£¡£
Îó²îÑéÖ¤
ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£¡£¡£
ÐÞ¸´½¨Òé
£¨1£©ÊµÊ±¸üв¹¶¡£¡£¡£¡£¡£¡£¡£ºhttps://github.com/Netflix/security-bulletins/tree/master/advisories/third-party/2019-001¡£¡£¡£¡£¡£¡£¡£
£¨2£©½ûÓÃSACK´¦Öóͷ£echo 0 > /proc/sys/net/ipv4/tcp_sack
£¨3£©Ê¹ÓùýÂËÆ÷À´×èÖ¹¹¥»÷
https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-001/block-low-mss/README.md
´Ë»º½âÐèÒª½ûÓÃTCP̽²âʱÓÐÓ㨼´ÔÚ/etc/sysctl.confÎļþÖн«net.ipv4.tcp_mtu_probingsysctlÉèÖÃΪ0£©
£¨4£©RedHatÓû§¿ÉÒÔʹÓÃÒÔϽÅÔÀ´¼ì²éϵͳÊÇ·ñ±£´æÎó²î
https://access.redhat.com/sites/default/files/cve-2019-11477--2019-06-17-1629.sh
²Î¿¼Á´½Ó