LinuxÄÚºËÖÐTCP SACKÔ¶³Ì¾Ü¾øÐ§ÀÍÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-06-19

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-11477£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-11478£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-11479£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾

Ó°ÏìLinux ÄÚºË2.6.29¼°ÒÔÉϰ汾


Îó²î¸ÅÊö


2019Äê6ÔÂ18ÈÕ£¬£¬£¬£¬RedHat¹ÙÍøÐû²¼±¨¸æ£ºÇå¾²Ñо¿Ö°Ô±ÔÚLinuxÄں˴¦Öóͷ£TCP

SACKÊý¾Ý°üÄ£¿£¿£¿£¿£¿£¿éÖз¢Ã÷ÁËÈý¸öÎó²î£¬£¬£¬£¬CVE±àºÅΪCVE-2019-11477¡¢CVE-2019-11478ºÍCVE-2019-11479¡£¡£¡£¡£¡£¡£¡£


CVE-2019-11477 SACK PanicÎó²îͨ¹ý¡°ÔÚ¾ßÓнÏСֵµÄTCP MSSµÄTCPÅþÁ¬ÉÏ·¢ËÍÈ«ÐÄÉè¼ÆµÄSACK¶ÎÐòÁС±À´Ê¹Ó㬣¬£¬£¬Õâ»á´¥·¢ÕûÊýÒç³ö¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îÄܹ»½µµÍϵͳÔËÐÐЧÂÊ£¬£¬£¬£¬²¢¿ÉÄܱ»Ô¶³Ì¹¥»÷ÕßÓÃÓھܾøÐ§À͹¥»÷£¬£¬£¬£¬Ó°ÏìˮƽÑÏÖØ¡£¡£¡£¡£¡£¡£¡£


CVE-2019-11478 SACK SlownessÎó²îͨ¹ý·¢ËÍ¡°Ò»¸öÈ«ÐÄÉè¼ÆµÄSACKÐòÁÐÀ´ÆÊÎöTCPÖØ´«ÐÐÁС±À´Ê¹Ó㬣¬£¬£¬¶øCVE-2019-11479Îó²îͨ¹ý·¢ËÍ¡°¾ßÓеÍMSSÖµµÄÈ«ÐÄÖÆ×÷µÄÊý¾Ý°ü¡±À´Ê¹ÓÃÔÊÐí¹¥»÷Õß´¥·¢DoS¡£¡£¡£¡£¡£¡£¡£


CVE-2019-5599ÊÇCVE-2019-11478µÄFreeBSD°æ±¾£¬£¬£¬£¬ËüʹÓÃRACK TCP¿ÍÕ»Ó°ÏìFreeBSD 12µÄ×°Ö㬣¬£¬£¬²¢ÇÒ¿ÉÒÔͨ¹ýÌṩ¡°Ò»¸öÈ«ÐÄÉè¼ÆµÄSACKÐòÁÐÀ´ÆÆËðRACK·¢ËÍÓ³É䡱¡£¡£¡£¡£¡£¡£¡£


¶ÔÎÒ¹ú¾³ÄÚʹÓÃLinux²Ù×÷ϵͳµÄЧÀÍÆ÷¾ÙÐÐͳ¼Æ£¬£¬£¬£¬Ð§¹ûÏÔʾÎÒ¹ú¾³ÄÚ¿ª·Å»¥ÁªÍø¶Ë¿ÚµÄLinuxЧÀÍÆ÷ÊýĿԼΪ202Íǫ̀¡£¡£¡£¡£¡£¡£¡£°´ÂþÑÜÇøÍ³¼ÆÀ´¿´£¬£¬£¬£¬ÅÅÃûǰÈýµÄÊ¡·ÝÊǹ㶫ʡ¡¢Õã½­Ê¡ºÍ±±¾©ÊС£¡£¡£¡£¡£¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£¡£¡£


ÐÞ¸´½¨Òé


£¨1£©ÊµÊ±¸üв¹¶¡£¡£¡£¡£¡£¡£¡£ºhttps://github.com/Netflix/security-bulletins/tree/master/advisories/third-party/2019-001¡£¡£¡£¡£¡£¡£¡£

£¨2£©½ûÓÃSACK´¦Öóͷ£
echo 0 > /proc/sys/net/ipv4/tcp_sack
£¨3£©Ê¹ÓùýÂËÆ÷À´×èÖ¹¹¥»÷
https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-001/block-low-mss/README.md
´Ë»º½âÐèÒª½ûÓÃTCP̽²âʱÓÐÓ㨼´ÔÚ/etc/sysctl.confÎļþÖн«net.ipv4.tcp_mtu_probingsysctlÉèÖÃΪ0£©
£¨4£©RedHatÓû§¿ÉÒÔʹÓÃÒÔϽÅÔ­À´¼ì²éϵͳÊÇ·ñ±£´æÎó²î

https://access.redhat.com/sites/default/files/cve-2019-11477--2019-06-17-1629.sh


²Î¿¼Á´½Ó


https://access.redhat.com/security/vulnerabilities/tcpsack