Netflix Uncovers TCP Bugs Within The Linux & FreeBSD Kernels

Written by Michael Larabel in Linux Security on 18 June 2019 at 06:51 AM EDT. 30 Comments
LINUX SECURITY
As Netflix's first security bulletin for 2019, they warned of TCP-based remote denial of service vulnerabilities affecting both Linux and FreeBSD. These vulnerabilities are rated "critical" but already being corrected within the latest Git code.

On Monday, Netflix warned of multiple TCP-based remote denial of service bugs. The most serious of these bugs has even been dubbed "SACK Panic" as it could allow remotely-triggering kernel panics using recent versions of the Linux kernel while going back to Linux 2.6.29. The SACK Panic situation can lead to a kernel panic via integer overflows.

Other vulnerabilities include excessive resource usage in different situations. Details in full via the security bulletin.

With the latest Linux kernel Git as of last night, the vulnerabilities are addressed and should soon be appearing in kernel point releases too.
Related News
About The Author
Michael Larabel

Michael Larabel is the principal author of Phoronix.com and founded the site in 2004 with a focus on enriching the Linux hardware experience. Michael has written more than 20,000 articles covering the state of Linux hardware support, Linux performance, graphics drivers, and other topics. Michael is also the lead developer of the Phoronix Test Suite, Phoromatic, and OpenBenchmarking.org automated benchmarking software. He can be followed via Twitter, LinkedIn, or contacted via MichaelLarabel.com.

Popular News This Week