LinuxÄÚºËÖÐTCP SACKÔ¶³Ì¾Ü¾øÐ§ÀÍÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-06-19

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-11477£¬ £¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬ £¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5£¬ £¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-11478£¬ £¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬ £¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-11479£¬ £¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬ £¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾

Ó°ÏìLinux ÄÚºË2.6.29¼°ÒÔÉϰ汾


Îó²î¸ÅÊö


2019Äê6ÔÂ18ÈÕ£¬ £¬£¬£¬£¬£¬RedHat¹ÙÍøÐû²¼±¨¸æ£ºÇå¾²Ñо¿Ö°Ô±ÔÚLinuxÄں˴¦Öóͷ£TCP

SACKÊý¾Ý°üÄ£¿£¿£¿ £¿£¿éÖз¢Ã÷ÁËÈý¸öÎó²î£¬ £¬£¬£¬£¬£¬CVE±àºÅΪCVE-2019-11477¡¢CVE-2019-11478ºÍCVE-2019-11479¡£¡£¡£¡£¡£


CVE-2019-11477 SACK PanicÎó²îͨ¹ý¡°ÔÚ¾ßÓнÏСֵµÄTCP MSSµÄTCPÅþÁ¬ÉÏ·¢ËÍÈ«ÐÄÉè¼ÆµÄSACK¶ÎÐòÁС±À´Ê¹Ó㬠£¬£¬£¬£¬£¬Õâ»á´¥·¢ÕûÊýÒç³ö¡£¡£¡£¡£¡£¸ÃÎó²îÄܹ»½µµÍϵͳÔËÐÐЧÂÊ£¬ £¬£¬£¬£¬£¬²¢¿ÉÄܱ»Ô¶³Ì¹¥»÷ÕßÓÃÓھܾøÐ§À͹¥»÷£¬ £¬£¬£¬£¬£¬Ó°ÏìˮƽÑÏÖØ¡£¡£¡£¡£¡£


CVE-2019-11478 SACK SlownessÎó²îͨ¹ý·¢ËÍ¡°Ò»¸öÈ«ÐÄÉè¼ÆµÄSACKÐòÁÐÀ´ÆÊÎöTCPÖØ´«ÐÐÁС±À´Ê¹Ó㬠£¬£¬£¬£¬£¬¶øCVE-2019-11479Îó²îͨ¹ý·¢ËÍ¡°¾ßÓеÍMSSÖµµÄÈ«ÐÄÖÆ×÷µÄÊý¾Ý°ü¡±À´Ê¹ÓÃÔÊÐí¹¥»÷Õß´¥·¢DoS¡£¡£¡£¡£¡£


CVE-2019-5599ÊÇCVE-2019-11478µÄFreeBSD°æ±¾£¬ £¬£¬£¬£¬£¬ËüʹÓÃRACK TCP¿ÍÕ»Ó°ÏìFreeBSD 12µÄ×°Ö㬠£¬£¬£¬£¬£¬²¢ÇÒ¿ÉÒÔͨ¹ýÌṩ¡°Ò»¸öÈ«ÐÄÉè¼ÆµÄSACKÐòÁÐÀ´ÆÆËðRACK·¢ËÍÓ³É䡱¡£¡£¡£¡£¡£


¶ÔÎÒ¹ú¾³ÄÚʹÓÃLinux²Ù×÷ϵͳµÄЧÀÍÆ÷¾ÙÐÐͳ¼Æ£¬ £¬£¬£¬£¬£¬Ð§¹ûÏÔʾÎÒ¹ú¾³ÄÚ¿ª·Å»¥ÁªÍø¶Ë¿ÚµÄLinuxЧÀÍÆ÷ÊýĿԼΪ202Íǫ̀¡£¡£¡£¡£¡£°´ÂþÑÜÇøÍ³¼ÆÀ´¿´£¬ £¬£¬£¬£¬£¬ÅÅÃûǰÈýµÄÊ¡·ÝÊǹ㶫ʡ¡¢Õã½­Ê¡ºÍ±±¾©ÊС£¡£¡£¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£


ÐÞ¸´½¨Òé


£¨1£©ÊµÊ±¸üв¹¶¡£¡£¡£¡£¡£ºhttps://github.com/Netflix/security-bulletins/tree/master/advisories/third-party/2019-001¡£¡£¡£¡£¡£

£¨2£©½ûÓÃSACK´¦Öóͷ£
echo 0 > /proc/sys/net/ipv4/tcp_sack
£¨3£©Ê¹ÓùýÂËÆ÷À´×èÖ¹¹¥»÷
https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-001/block-low-mss/README.md
´Ë»º½âÐèÒª½ûÓÃTCP̽²âʱÓÐÓ㨼´ÔÚ/etc/sysctl.confÎļþÖн«net.ipv4.tcp_mtu_probingsysctlÉèÖÃΪ0£©
£¨4£©RedHatÓû§¿ÉÒÔʹÓÃÒÔϽÅÔ­À´¼ì²éϵͳÊÇ·ñ±£´æÎó²î

https://access.redhat.com/sites/default/files/cve-2019-11477--2019-06-17-1629.sh


²Î¿¼Á´½Ó


https://access.redhat.com/security/vulnerabilities/tcpsack