LinuxÄÚºËÖÐTCP SACKÔ¶³Ì¾Ü¾øÐ§ÀÍÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-06-19

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-11477£¬£¬£¬£¬ £¬ £¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬ £¬ £¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5£¬£¬£¬£¬ £¬ £¬£¬£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-11478£¬£¬£¬£¬ £¬ £¬£¬£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬£¬£¬£¬ £¬ £¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-11479£¬£¬£¬£¬ £¬ £¬£¬£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬£¬£¬£¬ £¬ £¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾

Ó°ÏìLinux ÄÚºË2.6.29¼°ÒÔÉϰ汾


Îó²î¸ÅÊö


2019Äê6ÔÂ18ÈÕ£¬£¬£¬£¬ £¬ £¬£¬£¬RedHat¹ÙÍøÐû²¼±¨¸æ£ºÇå¾²Ñо¿Ö°Ô±ÔÚLinuxÄں˴¦Öóͷ£TCP

SACKÊý¾Ý°üÄ£¿£¿£¿£¿£¿£¿£¿éÖз¢Ã÷ÁËÈý¸öÎó²î£¬£¬£¬£¬ £¬ £¬£¬£¬CVE±àºÅΪCVE-2019-11477¡¢CVE-2019-11478ºÍCVE-2019-11479 ¡£¡£¡£¡£¡£ ¡£¡£¡£


CVE-2019-11477 SACK PanicÎó²îͨ¹ý¡°ÔÚ¾ßÓнÏСֵµÄTCP MSSµÄTCPÅþÁ¬ÉÏ·¢ËÍÈ«ÐÄÉè¼ÆµÄSACK¶ÎÐòÁС±À´Ê¹Ó㬣¬£¬£¬ £¬ £¬£¬£¬Õâ»á´¥·¢ÕûÊýÒç³ö ¡£¡£¡£¡£¡£ ¡£¡£¡£¸ÃÎó²îÄܹ»½µµÍϵͳÔËÐÐЧÂÊ£¬£¬£¬£¬ £¬ £¬£¬£¬²¢¿ÉÄܱ»Ô¶³Ì¹¥»÷ÕßÓÃÓھܾøÐ§À͹¥»÷£¬£¬£¬£¬ £¬ £¬£¬£¬Ó°ÏìˮƽÑÏÖØ ¡£¡£¡£¡£¡£ ¡£¡£¡£


CVE-2019-11478 SACK SlownessÎó²îͨ¹ý·¢ËÍ¡°Ò»¸öÈ«ÐÄÉè¼ÆµÄSACKÐòÁÐÀ´ÆÊÎöTCPÖØ´«ÐÐÁС±À´Ê¹Ó㬣¬£¬£¬ £¬ £¬£¬£¬¶øCVE-2019-11479Îó²îͨ¹ý·¢ËÍ¡°¾ßÓеÍMSSÖµµÄÈ«ÐÄÖÆ×÷µÄÊý¾Ý°ü¡±À´Ê¹ÓÃÔÊÐí¹¥»÷Õß´¥·¢DoS ¡£¡£¡£¡£¡£ ¡£¡£¡£


CVE-2019-5599ÊÇCVE-2019-11478µÄFreeBSD°æ±¾£¬£¬£¬£¬ £¬ £¬£¬£¬ËüʹÓÃRACK TCP¿ÍÕ»Ó°ÏìFreeBSD 12µÄ×°Ö㬣¬£¬£¬ £¬ £¬£¬£¬²¢ÇÒ¿ÉÒÔͨ¹ýÌṩ¡°Ò»¸öÈ«ÐÄÉè¼ÆµÄSACKÐòÁÐÀ´ÆÆËðRACK·¢ËÍÓ³É䡱 ¡£¡£¡£¡£¡£ ¡£¡£¡£


¶ÔÎÒ¹ú¾³ÄÚʹÓÃLinux²Ù×÷ϵͳµÄЧÀÍÆ÷¾ÙÐÐͳ¼Æ£¬£¬£¬£¬ £¬ £¬£¬£¬Ð§¹ûÏÔʾÎÒ¹ú¾³ÄÚ¿ª·Å»¥ÁªÍø¶Ë¿ÚµÄLinuxЧÀÍÆ÷ÊýĿԼΪ202Íǫ̀ ¡£¡£¡£¡£¡£ ¡£¡£¡£°´ÂþÑÜÇøÍ³¼ÆÀ´¿´£¬£¬£¬£¬ £¬ £¬£¬£¬ÅÅÃûǰÈýµÄÊ¡·ÝÊǹ㶫ʡ¡¢Õã½­Ê¡ºÍ±±¾©ÊÐ ¡£¡£¡£¡£¡£ ¡£¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP ¡£¡£¡£¡£¡£ ¡£¡£¡£


ÐÞ¸´½¨Òé


£¨1£©ÊµÊ±¸üв¹¶ ¡£¡£¡£¡£¡£ ¡£¡£¡£ºhttps://github.com/Netflix/security-bulletins/tree/master/advisories/third-party/2019-001 ¡£¡£¡£¡£¡£ ¡£¡£¡£

£¨2£©½ûÓÃSACK´¦Öóͷ£
echo 0 > /proc/sys/net/ipv4/tcp_sack
£¨3£©Ê¹ÓùýÂËÆ÷À´×èÖ¹¹¥»÷
https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-001/block-low-mss/README.md
´Ë»º½âÐèÒª½ûÓÃTCP̽²âʱÓÐÓ㨼´ÔÚ/etc/sysctl.confÎļþÖн«net.ipv4.tcp_mtu_probingsysctlÉèÖÃΪ0£©
£¨4£©RedHatÓû§¿ÉÒÔʹÓÃÒÔϽÅÔ­À´¼ì²éϵͳÊÇ·ñ±£´æÎó²î

https://access.redhat.com/sites/default/files/cve-2019-11477--2019-06-17-1629.sh


²Î¿¼Á´½Ó


https://access.redhat.com/security/vulnerabilities/tcpsack