Netflix researcher spots TCP SACK flaws in Linux and FreeBSD

Three vulnerabilities have been discovered in the FreeBSD and Linux kernels through which attackers could induce a denial-of-service by clogging networking I/O on affected systems. Uncovered by Netflix Information Security’s Jonathan Looney (yes, Netflix has a cybersecurity division), we’ll start with the most critical, dubbed ‘SACK Panic’, also identified as CVE-2019-11477.

Read full article on Naked Security

 


Date:

Categorie(s):