/?pid=new-vulnerabilities-may-let-hackers-remotely-sack-linux-20907

Updated:04:26 AM EDT Apr 18


this is ggmania.com subsite New vulnerabilities may let hackers remotely SACK Linux - TechAmok

New vulnerabilities may let hackers remotely SACK Linux - [security]
06:09 PM EDT - Jun,18 2019 - post a comment

The Linux and FreeBSD operating systems contain newly discovered vulnerabilities that make it easy for hackers to remotely crash servers and disrupt communications, researchers have warned. OS distributors are advising users to install patches when available or to make system settings that lower the chances of successful exploits. The most severe of the vulnerabilities, dubbed SACK Panic, can be exploited by sending a specially crafted sequence of TCP Selective ACKnowledgements to a vulnerable computer or server. The system will respond by crashing, or in the parlance of engineers, entering a kernel panic. Successful exploitation of this vulnerability, tracked as CVE-2019-11477, results in a remote denial of service (DoS). A second vulnerability also works by sending a series of malicious SACKs that consumes computing resources of the vulnerable system. Exploits most commonly work by fragmenting a queue reserved for retransmitting TCP packets. In some OS versions, attackers can cause what's known as an "expensive linked-list walk for subsequent SACKs." This can result in additional fragmentation, which has been dubbed "SACK slowness." Exploitation of this vulnerability, tracked as CVE-2019-11478, drastically degrades system performance and may eventually cause a complete DoS. Both of these vulnerabilities exploit the way the OSes handle the above-mentioned TCP Selective ACKnowledgement (abbreviated SACK). SACK is a mechanism that allows a computer on the receiving end of a communication to apprise the sender of what segments have been successfully sent so that any lost ones can be resent. The parties set up the use of SACK during the three-way handshake that establishes the initial connection. The exploits work by overflowing a queue that stores received packets. A vulnerability in FreeBSD 12 (tracked as CVE-2019-5599) works similarly to CVE-2019-11478 but instead interacts with the RACK send map of that OS. A fourth vulnerability, tracked as CVE-2019-11479, can slow down affected systems by lowering the maximum segment size for a TCP connection. The setting causes vulnerable systems to send responses across multiple TCP segments, each of which contains only 8 bytes of data. Exploits cause the system to consume large amounts of bandwidth and resources in a way that degrades system performance. Maximum segment size is a setting contained in the header of a TCP packet that specifies the total amount of data contained in a reconstructed segment.

The vulnerabilities were discovered by researchers from Netflix and publicly reported Monday in a disclosure that was coordinated with the affected OS developers. Linux distributions have either released patches that fix the vulnerabilities or have recommended configuration changes that mitigate them. Workarounds include blocking connections with a low MSS, disabling SACK processing, or temporarily disabling the RACK TCP stack. These changes may break legitimate connections, and in the case of the RACK TCP stack being disabled, an attacker still may be able to cause an expensive linked-list walk for subsequent SACKs received for the same TCP connection.

The above-linked Netflix disclosure and this post from security firm Tenable are good places to get additional details. Affected OS users should consult with the developers of their distribution. Redhat has a good write-up here, and write-ups from Ubuntu and Amazon are here and here.


Short overview of recent news articles

I Will Build You a PC Right Now! (Apr,18 2024 )

These games carry REAL security risks! BEWARE! (Apr,17 2024 )

Visible First to Offer Annual Payment Plan, with Discount up to 26% (Apr,17 2024 )

Is Coding Still Worth Learning in 2024? (Apr,17 2024 )

All New Atlas - Boston Dynamics (Apr,17 2024 )

The NEW Chip Inside Your Phone! (NPUs) (Apr,16 2024 )

XPS 14 vs 14" MacBook Pro - Apple just KILLED Intel! (Apr,16 2024 )

The Most 2024 Laptop - Razer Blade 14 Review (Apr,15 2024 )

NEVER install these programs on your PC... EVER!!! (Apr,15 2024 )

Use Live Translate on Galaxy S24 series to translate a call's (Apr,14 2024 )

I Tried a Non-Invasive Blood Sugar Watch. Miracle or Scam? (Apr,14 2024 )

Samsung Galaxy Ring - This Just Got Interesting (Apr,13 2024 )

Piracy Is Over Party - WAN Show April 12, 2024 (Apr,13 2024 )

Conan O'Brien Needs a Doctor While Eating Spicy Wings (Apr,13 2024 )

Beatbox Jcob recreats every sound (Apr,13 2024 )

Intel is Gunning for NVIDIA (Apr,13 2024 )

Building a Budget DIY Home Surveillance System (Apr,13 2024 )

Lenovo Yoga Buyers Guide - What's the Best Thin and Light Laptop (Apr,12 2024 )

DARK MATTER Trailer (2024) New Sci-Fi Movies 4K (Apr,11 2024 )

How to Build a PC, the last guide you'll ever need! (2024 Update) (Apr,11 2024 )

Intel 300 CPU Review - The Pentium Replacement is Finally Here... (Apr,10 2024 )

Wubuntu, the Dubious Linux Windows (Apr,10 2024 )

A Lite Version Of Windows 11 To Be Released This Year (Apr,09 2024 )

This $150 Smartphone might be All You Need (Apr,09 2024 )

I Can't Believe These are Real - Reacting to Ridiculous PCs on (Apr,09 2024 )

A new video shows AirPower prototype charging an Apple Watch (Apr,08 2024 )

Google Deleting Incognito Data, Intel $7B Foundry Loss, $350+ Curved (Apr,08 2024 )

20 COOL GADGETS YOU SHOULD SEE (Apr,08 2024 )

New HTTP/2 vulnerability leaves servers in danger of devastating DoS (Apr,08 2024 )

3D Printed PC Fan Test: Does the Anti-Stall Ring Boost Performance? (Apr,07 2024 )

The Greatest GPU of All Time: NVIDIA GTX 1080 Ti & GTX 1080 2024 (Apr,06 2024 )

Top NEW RELEASES on Netflix in APRIL 2024 (Apr,06 2024 )

Magician vs Slow-Mo Camera (Skill Challenge) (Apr,05 2024 )

Re-Ranking All Current GPUs From Worst to Best (2024 Update) (Apr,05 2024 )

Ripple to ISSUE STABLE COIN utilizing XRP AUTO-Bridging Function (Apr,04 2024 )

HW News - Intel Battlemage Appears, Open Source GPU, Xbox Handheld (Apr,04 2024 )

Vivo X Fold 3 Pro Hands-On: The New Best Foldable Hardware (Apr,03 2024 )

OPNSense: Protect Your Home LAN With a Transparent Filtering Bridge (Apr,02 2024 )

Ultimate Guide to Virtualization: Run MacOS, Linux, and Windows all (Mar,31 2024 )

This MIGHT be the best NAS on the market (Mar,31 2024 )

What do Zen 5, Arc Battlemage and NVIDIA RTX 50 GPUs Have In Common? (Mar,31 2024 )

They FIXED the Dual Chamber Problem! (Mar,31 2024 )

Paying for Cloud Storage is Stupid (Mar,30 2024 )

Entire Case Company Built on Literal Theft (Mar,30 2024 )

Red Hat warns of backdoor in XZ tools used by most Linux distros (Mar,30 2024 )

AMD Ryzen 7 7800X3D vs. Ryzen 9 7900X3D vs. Ryzen 9 7950X3D, Gaming (Mar,30 2024 )

I Need a Home Theater PC... NOW! - NVIDIA RTX HDR (Mar,30 2024 )

Whatever Happened To Acer? (Mar,29 2024 )

Intel's Battle Has Just Begun (Mar,28 2024 )

Unreal Physics is a new free game on Steam (Mar,27 2024 )

>> News Archive <<

TechAmok - Privacy Policy        loading time:0.01secs