HomeSecurityNetflix: TCP protocol vulnerabilities in FreeBSD and Linux kernels

Netflix: TCP protocol vulnerabilities in FreeBSD and Linux kernels

Netflix security engineers have discovered and reported vulnerabilities in the TCP protocol in FreeBSD and Linux kernels. Among these vulnerabilities, the most serious is the “SACK Panic,” which allows an attacker to remotely attack Linux kernels.TCP

In total, four vulnerabilities were found, related to maximum segment size (MSS) and TCP Selective Acknowledgement (SACK). MSS is a parameter in the TCP header of a packet that determines the total amount of datathat a computer can receive in a single TCP segment. SACK is a mechanism that allows the recipient of data to inform the sender of all segments that have arrived successfully.

Later, Red Hat also described the specific vulnerabilities, their history, and the patches. Red Hat stated that exploitation of the vulnerabilities was limited to some denial-of-service attacks. It also added that there is no evidence that the vulnerabilities were used to leak data or gain complete control of infected systems.

Netflix: TCP protocol vulnerabilities in FreeBSD and Linux kernelsBelow are two of the vulnerabilities that were published:

SACK Panic (CVE-2019-11477)

Sack Panic, as mentioned above, is the most serious of the four vulnerabilities. A hacker can exploit it and cause an integer overflow, by sending a crafted sequence of SACKs, on a TCP connection with a small MSS value. This causes the operating system to malfunction and has difficulty recovering to its normal state. A reboot is required, thus causing a denial-of-service attack.

The SACK Panic vulnerability was detected in Linux 2.6.29 and later versions.

Excessive resource consumption due to low MSS values ​​(CVE-2019-11479)

An attacker can force the Linux kernel to split its responses into multiple TCP segments that host 8 bytes of data. This results in a larger bandwidth being required for the same amount of data.

This particular vulnerability was found in all Linux versions.

The Netflix team said that there are patches for these vulnerabilities and suggests some workarounds in the official report.

Red Hat said it will issue a “kpatch” that will be available to all customers running supported versions of Red Hat Enterprise Linux 7 or later. The company advises customers running affected versions to update immediately once it is released. More information about the steps to address the vulnerabilities is available on the official Red Hat website.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS