Live data from Hacker News

SACK Panic – Multiple TCP-based remote denial-of-service issues

access.redhat.com

1–10 of 134 posts

Re: SACK Panic – Multiple TCP-based remote denial-of-service issues

#3
post #2

Red Hat's article on these issues also provides further explanations: https://access.redhat.com/security/vulnerabilities/tcpsack

That seems to have a bit more information, so we switched to it from https://www.openwall.com/lists/oss-security/2019/06/17/5. Thanks!

Re: SACK Panic – Multiple TCP-based remote denial-of-service issues

#6
post #3
post #2

Red Hat's article on these issues also provides further explanations: https://access.redhat.com/security/vulnerabilities/tcpsack

That seems to have a bit more information, so we switched to it from https://www.openwall.com/lists/oss-security/2019/06/17/5 . Thanks!

The original link includes links to the patches. Fascinating how the SACK MSS problem seems to be a relatively simple situation nobody realized can occur.

Re: SACK Panic – Multiple TCP-based remote denial-of-service issues

#9
post #2

Red Hat's article on these issues also provides further explanations: https://access.redhat.com/security/vulnerabilities/tcpsack

There is also an ansible playbook on the resolve tab to easily apply the net.ipv4.tpc_sack workaround on all your hosts.

Re: SACK Panic – Multiple TCP-based remote denial-of-service issues

#10
post #4

That BUG_ON is a full up kernel panic? That's a pretty severe issue if so.

Yes. In all seriousness, this is a "drop everything and patch" situation, as soon as the patches are available.

It's a little bit more involved than a ping of death, but still, relatively easy to exploit.

Post reply on HN