Live data from Hacker News

SACK Panic – Multiple TCP-based remote denial-of-service issues

access.redhat.com

131–134 of 134 posts

Re: SACK Panic – Multiple TCP-based remote denial-of-service issues

#131

I'm collecting vendor links internally for work: Red Hat / CentOS https://access.redhat.com/security/vulnerabilities/tcpsack https://access.redhat.com/security/cve/cve-2019-11477 https://access.redhat.com/security/cve/cve-2019-11478 https://access.redhat.com/security/cve/cve-2019-11479 Ubuntu https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/SACKPanic https://people.canonical.com/~ubuntu-security/cve/2019/CVE-2... h…

Here's the info from F5 Networks:

https://support.f5.com/csp/article/K78234183

https://support.f5.com/csp/article/K26618426

https://support.f5.com/csp/article/K35421172

Re: SACK Panic – Multiple TCP-based remote denial-of-service issues

#132
post #101

Will any Android phones be affected, or they don't support segment offloading?

Android seems to be affected: https://android.googlesource.com/kernel/common/+/5d625e9b4a6... This might be fun... Edit: Don't know if segmentation offloading is on by default in Android, but on my default Arch kernel it is, so I wouldn't know why not.

It is impacted, but patches being present in kernel/common doesn't imply that since all of the upstream changes from the LTS branches are merged.

Re: SACK Panic – Multiple TCP-based remote denial-of-service issues

#134
post #131

I'm collecting vendor links internally for work: Red Hat / CentOS https://access.redhat.com/security/vulnerabilities/tcpsack https://access.redhat.com/security/cve/cve-2019-11477 https://access.redhat.com/security/cve/cve-2019-11478 https://access.redhat.com/security/cve/cve-2019-11479 Ubuntu https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/SACKPanic https://people.canonical.com/~ubuntu-security/cve/2019/CVE-2... h…

Here's the info from F5 Networks: https://support.f5.com/csp/article/K78234183 https://support.f5.com/csp/article/K26618426 https://support.f5.com/csp/article/K35421172

Apparently HN has a time limit on editing, I no longer see an Edit option on my comment. To add to yours (thx!), here are some additional vendors who are now live:

Fedora

https://lists.fedoraproject.org/archives/list/package-announ... (F29)

https://lists.fedoraproject.org/archives/list/package-announ... (F30)

CentOS

https://lists.centos.org/pipermail/centos-announce/2019-June... (v6)

https://lists.centos.org/pipermail/centos-announce/2019-June... (v7)

Post reply on HN