CNNVD-ID编号 | CNNVD-201906-681 | CVE编号 | CVE-2019-11477 |
发布时间 | 2019-06-18 | 更新时间 | 2020-12-02 |
漏洞类型 | 输入验证错误 | 漏洞来源 | Jonathan Looney (Netflix Information Security),这个漏洞是由Netflix研究者Jonathan Looney发现.,Jonathan Looney |
危险等级 | 高危 | 威胁类型 | 远程 |
厂商 | N/A |
Linux kernel是美国Linux基金会发布的开源操作系统Linux所使用的内核。
Linux kernel中的网络子系统处理TCP Selective Acknowledgment (SACK)片段的方法存在输入验证错误漏洞。攻击者可利用该漏洞造成拒绝服务。
目前厂商已发布升级了Linux kernel 输入验证错误漏洞的补丁,Linux kernel 输入验证错误漏洞的补丁获取链接:
https://git.kernel.org/pub/scm/linux/kernel/git/davem/net.git/commit/?id=3b4929f65b0d8249f19a50245cd88ed1a2f78cff
来源:MISC
来源:www.huawei.com
链接:https://www.huawei.com/cn/psirt/security-advisories/huawei-sa-20191204-01-kernel-cn
来源:MLIST
来源:MLIST
来源:CONFIRM
来源:MLIST
来源:MISC
链接:https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-001.md
来源:www.oracle.com
来源:MISC
链接:https://access.redhat.com/security/vulnerabilities/tcpsack
来源:REDHAT
来源:MISC
链接:http://packetstormsecurity.com/files/153346/Kernel-Live-Patch-Security-Notice-LSN-0052-1.html
来源:CONFIRM
链接:http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2020-010.txt
来源:CONFIRM
链接:https://cert-portal.siemens.com/productcert/pdf/ssa-462066.pdf
来源:access.redhat.com
来源:access.redhat.com
来源:access.redhat.com
来源:access.redhat.com
来源:access.redhat.com
来源:access.redhat.com
来源:access.redhat.com
来源:access.redhat.com
来源:access.redhat.com
来源:access.redhat.com
来源:access.redhat.com
来源:access.redhat.com
来源:access.redhat.com
来源:bugzilla.redhat.com
来源:git.kernel.org
来源:www.kernel.org
来源:REDHAT
来源:wiki.ubuntu.com
链接:https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/SACKPanic
来源:MISC
来源:MISC
链接:https://packetstormsecurity.com/files/154951/Kernel-Live-Patch-Security-Notice-LSN-0058-1.html
来源:CONFIRM
链接:https://www.vmware.com/security/advisories/VMSA-2019-0010.html
来源:CONFIRM
链接:https://kc.mcafee.com/corporate/index?page=content&id=SB10287
来源:MLIST
来源:CONFIRM
链接:https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2019-0006
来源:REDHAT
来源:CERT-VN
来源:usn.ubuntu.com
来源:usn.ubuntu.com
来源:kb.pulsesecure.net
链接:https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44193
来源:security.netapp.com
来源:MLIST
来源:support.citrix.com
来源:MISC
链接:https://packetstormsecurity.com/files/153346/Kernel-Live-Patch-Security-Notice-LSN-0052-1.html
来源:CONFIRM
链接:https://www.synology.com/security/advisory/Synology_SA_19_28
来源:MLIST
来源:CONFIRM
链接:https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20191225-01-kernel-en
来源:www.suse.com
链接:https://www.suse.com/support/update/announcement/2019/suse-su-20191530-1.html
来源:www.suse.com
链接:https://www.suse.com/support/update/announcement/2019/suse-su-20191529-1.html
来源:www.suse.com
链接:https://www.suse.com/support/update/announcement/2019/suse-su-20191532-1.html
来源:www.suse.com
链接:https://www.suse.com/support/update/announcement/2019/suse-su-20191536-1.html
来源:www.ibm.com
来源:www.ibm.com
来源:www.ibm.com
来源:www.ibm.com
来源:www.ibm.com
来源:www.suse.com
链接:https://www.suse.com/support/update/announcement/2019/suse-su-20191550-1.html
来源:www.suse.com
链接:https://www.suse.com/support/update/announcement/2019/suse-su-20191535-1.html
来源:www.suse.com
链接:https://www.suse.com/support/update/announcement/2019/suse-su-20191534-1.html
来源:www.suse.com
链接:https://www.suse.com/support/update/announcement/2019/suse-su-20191533-1.html
来源:www.suse.com
链接:https://www.suse.com/support/update/announcement/2019/suse-su-20191527-1.html
来源:www.suse.com
链接:https://www.suse.com/support/update/announcement/2019/suse-su-201914089-1.html
来源:www.suse.com
链接:https://www.suse.com/support/update/announcement/2019/suse-su-20192953-1.html
来源:www.suse.com
链接:https://www.suse.com/support/update/announcement/2019/suse-su-20192952-1.html
来源:www.suse.com
链接:https://www.suse.com/support/update/announcement/2019/suse-su-20192951-1.html
来源:www.suse.com
链接:https://www.suse.com/support/update/announcement/2019/suse-su-20192950-1.html
来源:www.suse.com
链接:https://www.suse.com/support/update/announcement/2019/suse-su-20192949-1.html
来源:www.suse.com
链接:https://www.suse.com/support/update/announcement/2019/suse-su-20192948-1.html
来源:www.suse.com
链接:https://www.suse.com/support/update/announcement/2019/suse-su-20192947-1.html
来源:www.suse.com
链接:https://www.suse.com/support/update/announcement/2019/suse-su-20192946-1.html
来源:www.suse.com
链接:https://www.suse.com/support/update/announcement/2019/suse-su-20191581-1.html
来源:www.suse.com
链接:https://www.suse.com/support/update/announcement/2019/suse-su-20191588-1.html
来源:fortiguard.com
来源:www.ibm.com
来源:www.auscert.org.au
来源:www.auscert.org.au
来源:www.ibm.com
来源:www.huawei.com
链接:https://www.huawei.com/cn/psirt/security-advisories/huawei-sa-20191225-01-kernel-cn
来源:www.auscert.org.au
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/153329/Linux-FreeBSD-TCP-Based-Denial-Of-Service.html
来源:www.ibm.com
来源:www.oracle.com
链接:https://www.oracle.com/security-alerts/cpujan2020verbose.html
来源:www.auscert.org.au
来源:www.auscert.org.au
来源:www.auscert.org.au
来源:us-cert.cisa.gov
来源:vigilance.fr
链接:https://vigilance.fr/vulnerability/Linux-kernel-denial-of-service-via-TCP-SACK-Low-MSS-Panic-29543
来源:www.us-cert.gov
来源:nvd.nist.gov
来源:www.ibm.com
来源:support.lenovo.com
链接:https://support.lenovo.com/us/en/product_security/LEN-29592
来源:www.auscert.org.au
来源:www.auscert.org.au
来源:www.auscert.org.au
来源:www.auscert.org.au
来源:www.oracle.com
来源:www.ibm.com
来源:www.securityfocus.com
来源:www.ibm.com
暂无