Linux PCs, Servers, Gadgets Can Be Crashed by 'Ping of Death' Network Packets

Peter Reutemann <[email protected]>
Newsgroups gmane.org.user-groups.linux.waikato
Message-ID <CAHoQ12LOrhd0RwhYnKtUsCHDNZEaBddLGsCaa514_zKJSOThtA@mail.gmail.com>
'The Register reports that it is possible to crash network-facing
Linux servers, PCs, smartphones and tablets, and gadgets, or slow down
their network connections, by sending them a series of maliciously
crafted packets. It is also possible to hamper FreeBSD machines with
the same attack. Patches and mitigations are available, and can be
applied by hand if needed, or you can wait for a security fix to be
pushed or offered to your at-risk device. A key workaround is to set
/proc/sys/net/ipv4/tcp_sack to 0. At the heart of the drama is a
programming flaw dubbed SACK Panic aka CVE-2019-11477: this bug can be
exploited to remotely crash systems powered by Linux kernel version
2.6.29 or higher, which was released 10 years ago.'

-- source: https://linux.slashdot.org/story/19/06/17/2018227

Cheers, Peter
-- 
Peter Reutemann
Dept. of Computer Science
University of Waikato, NZ
+64 (7) 858-5174
http://www.cms.waikato.ac.nz/~fracpete/
http://www.data-mining.co.nz/
_______________________________________________
wlug mailing list | [email protected]
Unsubscribe: https://list.waikato.ac.nz/mailman/listinfo/wlug
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.