LinuxÄÚºËÖÐTCP SACKÔ¶³Ì¾Ü¾øÐ§ÀÍÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-06-19Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-11478£¬£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-11479£¬£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
Ó°ÏìLinux ÄÚºË2.6.29¼°ÒÔÉϰ汾
Îó²î¸ÅÊö
SACKÊý¾Ý°üÄ£¿£¿£¿£¿£¿£¿£¿éÖз¢Ã÷ÁËÈý¸öÎó²î£¬£¬£¬£¬£¬£¬£¬£¬CVE±àºÅΪCVE-2019-11477¡¢CVE-2019-11478ºÍCVE-2019-11479¡£¡£¡£¡£¡£¡£¡£¡£
CVE-2019-11477 SACK PanicÎó²îͨ¹ý¡°ÔÚ¾ßÓнÏСֵµÄTCP MSSµÄTCPÅþÁ¬ÉÏ·¢ËÍÈ«ÐÄÉè¼ÆµÄSACK¶ÎÐòÁС±À´Ê¹Ó㬣¬£¬£¬£¬£¬£¬£¬Õâ»á´¥·¢ÕûÊýÒç³ö¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îÄܹ»½µµÍϵͳÔËÐÐЧÂÊ£¬£¬£¬£¬£¬£¬£¬£¬²¢¿ÉÄܱ»Ô¶³Ì¹¥»÷ÕßÓÃÓھܾøÐ§À͹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬Ó°ÏìˮƽÑÏÖØ¡£¡£¡£¡£¡£¡£¡£¡£
CVE-2019-11478 SACK SlownessÎó²îͨ¹ý·¢ËÍ¡°Ò»¸öÈ«ÐÄÉè¼ÆµÄSACKÐòÁÐÀ´ÆÊÎöTCPÖØ´«ÐÐÁС±À´Ê¹Ó㬣¬£¬£¬£¬£¬£¬£¬¶øCVE-2019-11479Îó²îͨ¹ý·¢ËÍ¡°¾ßÓеÍMSSÖµµÄÈ«ÐÄÖÆ×÷µÄÊý¾Ý°ü¡±À´Ê¹ÓÃÔÊÐí¹¥»÷Õß´¥·¢DoS¡£¡£¡£¡£¡£¡£¡£¡£
CVE-2019-5599ÊÇCVE-2019-11478µÄFreeBSD°æ±¾£¬£¬£¬£¬£¬£¬£¬£¬ËüʹÓÃRACK TCP¿ÍÕ»Ó°ÏìFreeBSD 12µÄ×°Ö㬣¬£¬£¬£¬£¬£¬£¬²¢ÇÒ¿ÉÒÔͨ¹ýÌṩ¡°Ò»¸öÈ«ÐÄÉè¼ÆµÄSACKÐòÁÐÀ´ÆÆËðRACK·¢ËÍÓ³É䡱¡£¡£¡£¡£¡£¡£¡£¡£
¶ÔÎÒ¹ú¾³ÄÚʹÓÃLinux²Ù×÷ϵͳµÄЧÀÍÆ÷¾ÙÐÐͳ¼Æ£¬£¬£¬£¬£¬£¬£¬£¬Ð§¹ûÏÔʾÎÒ¹ú¾³ÄÚ¿ª·Å»¥ÁªÍø¶Ë¿ÚµÄLinuxЧÀÍÆ÷ÊýĿԼΪ202Íǫ̀¡£¡£¡£¡£¡£¡£¡£¡£°´ÂþÑÜÇøÍ³¼ÆÀ´¿´£¬£¬£¬£¬£¬£¬£¬£¬ÅÅÃûǰÈýµÄÊ¡·ÝÊǹ㶫ʡ¡¢Õã½Ê¡ºÍ±±¾©ÊС£¡£¡£¡£¡£¡£¡£¡£
Îó²îÑéÖ¤
ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£¡£¡£¡£
ÐÞ¸´½¨Òé
£¨1£©ÊµÊ±¸üв¹¶¡£¡£¡£¡£¡£¡£¡£¡£ºhttps://github.com/Netflix/security-bulletins/tree/master/advisories/third-party/2019-001¡£¡£¡£¡£¡£¡£¡£¡£
£¨2£©½ûÓÃSACK´¦Öóͷ£echo 0 > /proc/sys/net/ipv4/tcp_sack
£¨3£©Ê¹ÓùýÂËÆ÷À´×èÖ¹¹¥»÷
https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-001/block-low-mss/README.md
´Ë»º½âÐèÒª½ûÓÃTCP̽²âʱÓÐÓ㨼´ÔÚ/etc/sysctl.confÎļþÖн«net.ipv4.tcp_mtu_probingsysctlÉèÖÃΪ0£©
£¨4£©RedHatÓû§¿ÉÒÔʹÓÃÒÔϽÅÔÀ´¼ì²éϵͳÊÇ·ñ±£´æÎó²î
https://access.redhat.com/sites/default/files/cve-2019-11477--2019-06-17-1629.sh
²Î¿¼Á´½Ó


¾©¹«Íø°²±¸11010802024551ºÅ