AWS Bulletin: https://aws.amazon.com/security/security-bulletins/AWS-2019-... FYI if your instances are behind an Application Load Balancer or Classic Load Balancer then they are protected, but NOT if they are behind a Network Load Balancer. A patched kernel is available for Amazon Linux 1 and 2, so you won't have to disable SACK. You can run "sudo yum update kernel" to get it, but of course you have to reboot. Updat…
Even if your instances are behind ALBs or ELBs they may not be protected if they make outbound connections to the internet.
As each direction of a TCP connection has its own MSS, it would make sense that an attacker's server could exploit this.