{"id":5982,"date":"2019-12-29T21:22:56","date_gmt":"2019-12-29T13:22:56","guid":{"rendered":"https:\/\/aqzt.com\/5982.html"},"modified":"2020-07-11T20:15:13","modified_gmt":"2020-07-11T12:15:13","slug":"%e9%a2%84%e8%ad%a6linux-%e5%86%85%e6%a0%b8tcp-sack%e6%9c%ba%e5%88%b6%e8%bf%9c%e7%a8%8b%e6%8b%92%e7%bb%9d%e6%9c%8d%e5%8a%a1%e6%bc%8f%e6%b4%9e","status":"publish","type":"post","link":"https:\/\/aqzt.com\/5982.html","title":{"rendered":"\u9884\u8b66Linux \u5185\u6838TCP SACK\u673a\u5236\u8fdc\u7a0b\u62d2\u7edd\u670d\u52a1\u6f0f\u6d1e"},"content":{"rendered":"<p style=\"text-align:start;line-height:24px\">2019\u5e746\u670818\u65e5\uff0c\u672c\u7ad9\u5b89\u5168\u4e13\u9898\u76d1\u63a7\u5230\u56fd\u5916\u67d0\u5b89\u5168\u7814\u7a76\u7ec4\u7ec7\u62ab\u9732Linux \u5185\u6838TCP SACK\u673a\u5236\u5b58\u5728\u7f3a\u9677\uff0c\u53ef\u5bfc\u81f4\u8fdc\u7a0b\u62d2\u7edd\u670d\u52a1\u3002CVE\u7f16\u53f7\u4e3aCVE-2019-11477\u3001CVE-2019-11478\u548cCVE-2019-11479\u3002<\/p>\n<p><\/p>\n<p style=\"text-align:start;line-height:24px\"><strong>\u6f0f\u6d1e\u63cf\u8ff0<\/strong><\/p>\n<p>Linux \u5185\u68382.6.29\u53ca\u4e4b\u540e\u7248\u672c\u5728\u5904\u7406TCP SACK\u673a\u5236\u65f6\u5b58\u5728\u7f3a\u9677\uff0c\u5bfc\u81f4\u6574\u6570\u6ea2\u51fa\u6f0f\u6d1e\uff0c\u653b\u51fb\u8005\u53ef\u4ee5\u6784\u9020\u7279\u5b9a\u7684SACK\u5305\uff0c\u8fdc\u7a0b\u89e6\u53d1Linux\u670d\u52a1\u5668\u5185\u6838\u6a21\u5757\u6ea2\u51fa\u6f0f\u6d1e\uff0c\u5b9e\u73b0\u8fdc\u7a0b\u62d2\u7edd\u670d\u52a1\u653b\u51fb\u3002<\/p>\n<p><strong>\u6f0f\u6d1e\u8bc4\u7ea7<\/strong><\/p>\n<p style=\"text-align:start;line-height:24px\">CVE-2019-11477&nbsp;\u9ad8\u5371<\/p>\n<p style=\"text-align:start;line-height:24px\">CVE-2019-11478&nbsp;\u4e2d\u5371<\/p>\n<p style=\"text-align:start;line-height:24px\">CVE-2019-11479&nbsp;\u4e2d\u5371<\/p>\n<p><strong>\u5b89\u5168\u4fee\u590d\u5efa\u8bae<\/strong><\/p>\n<p><\/p>\n<p><strong>\u6ce8\uff1a\u4ee5\u4e0b\u4efb\u610f\u4e00\u79cd\u4fee\u590d\u65b9\u5f0f\u90fd\u6709\u53ef\u80fd\u9020\u6210\u4e1a\u52a1\u4e0d\u53ef\u7528<\/strong><\/p>\n<p><\/p>\n<p>\u4e00\u3001\u7981\u7528SACK\u673a\u5236\u529f\u80fd\uff0c\u6267\u884c\u5982\u4e0b\u547d\u4ee4\uff1a<\/p>\n<p><\/p>\n<\/p>\n<pre>\n\n<div class=\"codecolorer-container text solarized-dark lang-bash\" style=\"overflow:auto;white-space:nowrap;width:800px;\"><table cellspacing=\"0\" cellpadding=\"0\"><tbody><tr><td class=\"line-numbers\"><div>1<br \/>2<br \/><\/div><\/td><td><div class=\"text codecolorer\">echo 0 &amp;gt; \/proc\/sys\/net\/ipv4\/tcp_sack<br \/>\nsysctl -w net.ipv4.tcp_sack=0<\/div><\/td><\/tr><\/tbody><\/table><\/div>\n\n<\/pre>\n<p><\/p>\n<p style=\"text-align:start;line-height:24px\">\u4e8c\u3001\u5347\u7ea7Linux\u5b89\u5168\u8865\u4e01(<strong>\u9700\u8981\u91cd\u542f\u670d\u52a1\u5668)<\/strong><\/p>\n<p><\/p>\n<p style=\"text-align:start;line-height:24px\">Ubuntu&nbsp;\u7cfb\u5217\uff1aapt-get update &amp;&amp; sudo apt-get install linux-image-generic&nbsp;\u6216\u4f7f\u7528<a href=\"https:\/\/yundunnext.console.aliyun.com\/?spm=a2c4g.11174386.n2.5.71f11051r2lstO&amp;p=sasnext#\/vulManage\/cn-hangzhou\" target=\"_blank\" class=\"\" rel=\"noopener noreferrer\"><strong>\u4e91\u5b89\u5168\u4e2d\u5fc3\u6f0f\u6d1e\u4e00\u952e\u4fee\u590d<\/strong><\/a>\u529f\u80fd\uff0c\u641c\u7d22\u6f0f\u6d1e\u7f16\u53f7\uff1aUSN-4017-1\uff1a<\/p>\n<p><\/p>\n<p style=\"text-align:start;line-height:24px\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/knowledgecloud.oss-cn-hangzhou.aliyuncs.com\/kc\/kc-media\/kc-oss-1561342778560-image.png\" width=\"700\" height=\"353\"><\/p>\n<p><\/p>\n<p><\/p>\n<p style=\"text-align:start;line-height:24px\">Centos&nbsp;\u7cfb\u5217\uff1ayum update kernel&nbsp;\u6216&nbsp;\u4f7f\u7528<a href=\"https:\/\/yundunnext.console.aliyun.com\/?spm=a2c4g.11174386.n2.5.71f11051r2lstO&amp;p=sasnext#\/vulManage\/cn-hangzhou\" target=\"_blank\" class=\"\" rel=\"noopener noreferrer\"><strong>\u4e91\u5b89\u5168\u4e2d\u5fc3\u6f0f\u6d1e\u4e00\u952e\u4fee\u590d<\/strong><\/a>\u529f\u80fd\uff0c\u641c\u7d22\u6f0f\u6d1e\u7f16\u53f7\uff1aRHSA-2019:1488\u548cRHSA-2019:1481\uff1a<\/p>\n<p><\/p>\n<p style=\"text-align:start;line-height:24px\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/knowledgecloud.oss-cn-hangzhou.aliyuncs.com\/kc\/kc-media\/kc-oss-1561011199196-image.png\" width=\"700\" height=\"119\"><\/p>\n<p style=\"text-align:start;line-height:24px\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/knowledgecloud.oss-cn-hangzhou.aliyuncs.com\/kc\/kc-media\/kc-oss-1561011283382-image.png\" width=\"700\" height=\"312\"><\/p>\n<p><\/p>\n<p style=\"text-align:start;line-height:24px\">\u5176\u4ed6Linux&nbsp;\u8865\u4e01\u53ef\u53c2\u8003\uff1a<a href=\"https:\/\/github.com\/Netflix\/security-bulletins\/tree\/master\/advisories\/third-party\/2019-001\" target=\"_self\" class=\"\" rel=\"noopener noreferrer\">https:\/\/github.com\/Netflix\/security-bulletins\/tree\/master\/advisories\/third-party\/2019-001<\/a><\/p>\n<p><\/p>\n<p><strong>\u76f8\u5173\u94fe\u63a5<\/strong><\/p>\n<p><a href=\"https:\/\/github.com\/Netflix\/security-bulletins\/tree\/master\/advisories\/third-party\" target=\"_self\" class=\"\" rel=\"noopener noreferrer\">https:\/\/github.com\/Netflix\/security-bulletins\/tree\/master\/advisories\/third-party<\/a><\/p>\n<p>RedHat\u7cfb\u7edf\u7528\u6237\u53ef\u4f7f\u7528\u5b98\u65b9\u811a\u672c\u68c0\u6d4b\u6f0f\u6d1e\u662f\u5426\u5b58\u5728\uff1a<a href=\"https:\/\/access.redhat.com\/sites\/default\/files\/cve-2019-11477--2019-06-17-1629.sh\" target=\"_blank\" class=\"\" rel=\"noopener noreferrer\">https:\/\/access.redhat.com\/sites\/default\/files\/cve-2019-11477&#8211;2019-06-17-1629.sh<\/a><\/p>\n<p><\/p>\n<\/p>\n<p style=\"text-align:start;line-height:24px\">\u6211\u4eec\u4f1a\u5173\u6ce8\u540e\u7eed\u8fdb\u5c55\uff0c\u8bf7\u968f\u65f6\u5173\u6ce8\u5b98\u65b9\u516c\u544a\u3002<\/p>\n<p style=\"text-align:start;line-height:24px\">\u5185\u5bb9\u6765\u81ea\u7f51\u7edc\uff0c\u5982\u6709\u4fb5\u72af\u5230\u60a8\u7684\u6743\u76ca\uff0c\u8bf7\u8054\u7cfb\u7ad9\u957fQQ7529997\uff0c\u6211\u4eec\u5c06\u53ca\u65f6\u5904\u7406\u3002<\/p>\n<p style=\"text-align:start;line-height:24px\"><\/p>\n<p style=\"text-align:right;line-height:24px\">\u5b89\u5168\u4e13\u9898<\/p>\n<p style=\"text-align:right;line-height:24px\">2019.6.18<\/p>\n","protected":false},"excerpt":{"rendered":"<p>2019\u5e746\u670818\u65e5\uff0c\u672c\u7ad9\u5b89\u5168\u4e13\u9898\u76d1\u63a7\u5230\u56fd\u5916\u67d0\u5b89\u5168\u7814\u7a76\u7ec4\u7ec7\u62ab\u9732Linux \u5185\u6838TCP SACK\u673a\u5236\u5b58\u5728\u7f3a\u9677\uff0c\u53ef\u5bfc\u81f4\u8fdc\u7a0b\u62d2\u7edd\u670d\u52a1\u3002CVE\u7f16\u53f7\u4e3aCVE-2019-11477\u3001CVE-2019-11478\u548cCVE-2019-11479\u3002 \u6f0f\u6d1e\u63cf\u8ff0 Linux \u5185\u68382.6.29\u53ca\u4e4b\u540e\u7248\u672c\u5728\u5904\u7406TCP SACK\u673a\u5236\u65f6\u5b58\u5728\u7f3a\u9677\uff0c\u5bfc\u81f4\u6574\u6570\u6ea2\u51fa\u6f0f\u6d1e\uff0c\u653b\u51fb\u8005\u53ef\u4ee5\u6784\u9020\u7279\u5b9a\u7684SACK\u5305\uff0c\u8fdc\u7a0b\u89e6\u53d1Linux\u670d\u52a1\u5668\u5185\u6838\u6a21\u5757\u6ea2\u51fa\u6f0f\u6d1e\uff0c\u5b9e\u73b0\u8fdc\u7a0b\u62d2\u7edd\u670d\u52a1\u653b\u51fb\u3002 \u6f0f\u6d1e\u8bc4\u7ea7 CVE-2019-11477&nbsp;\u9ad8\u5371 CVE-2019-11478&#038;<\/p>\n","protected":false},"author":1,"featured_media":6522,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_bbp_topic_count":0,"_bbp_reply_count":0,"_bbp_total_topic_count":0,"_bbp_total_reply_count":0,"_bbp_voice_count":0,"_bbp_anonymous_reply_count":0,"_bbp_topic_count_hidden":0,"_bbp_reply_count_hidden":0,"_bbp_forum_subforum_count":0,"footnotes":""},"categories":[27],"tags":[292,17,176,23,9,270,13,10,11,22,20,269],"collection":[276],"_links":{"self":[{"href":"https:\/\/aqzt.com\/wp-json\/wp\/v2\/posts\/5982"}],"collection":[{"href":"https:\/\/aqzt.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/aqzt.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/aqzt.com\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/aqzt.com\/wp-json\/wp\/v2\/comments?post=5982"}],"version-history":[{"count":1,"href":"https:\/\/aqzt.com\/wp-json\/wp\/v2\/posts\/5982\/revisions"}],"predecessor-version":[{"id":6200,"href":"https:\/\/aqzt.com\/wp-json\/wp\/v2\/posts\/5982\/revisions\/6200"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/aqzt.com\/wp-json\/wp\/v2\/media\/6522"}],"wp:attachment":[{"href":"https:\/\/aqzt.com\/wp-json\/wp\/v2\/media?parent=5982"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/aqzt.com\/wp-json\/wp\/v2\/categories?post=5982"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/aqzt.com\/wp-json\/wp\/v2\/tags?post=5982"},{"taxonomy":"collection","embeddable":true,"href":"https:\/\/aqzt.com\/wp-json\/wp\/v2\/collection?post=5982"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}