Files
nexus/sreweekly/markdown/134/01-what-do-i-need-to-know-about-segmentsmack.md
2026-09-12 17:23:01 +08:00

68 lines
2.7 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# What Do I Need To Know about “SegmentSmack”
- **期号**: SRE Weekly Issue #134(2018-08-12)
- **作者**: Johannes B. Ullrich, PhD — SAN Technology Institute
- **链接**: https://isc.sans.edu/forums/diary/What Do I Need To Know about SegmentSmack/23964/
## 简介
The big news this week is SegmentSmack, a denial of service vulnerability in the Linux kernel that allows an attacker to cause high CPU consumption. Linked is a SANS Technology Institute researcher’s summary of the attack. Other coverage:AWSAkamaiFastlyCERTUbuntuRedhat
## 正文
# [What Do I Need To Know about "SegmentSmack"](https://isc.sans.edu/forums/diary/What+Do+I+Need+To+Know+about+SegmentSmack/23964/)
[3 comment(s)](https://isc.sans.edu/diary/What+Do+I+Need+To+Know+about+SegmentSmack/23964/#comments)
"SegmentSmack" is yet another branded vulnerability, also known as CVE-2018–5390. It hit the "news" yesterday. Succesful exploitation may lead to a denial of service against a targeted system. At this point, not a lot is known about this vulnerability. But here are some highlights:
- Linux Kernel 4.9 is vulnerable. Older versions are not vulnerable. However, some Linux distributions like RedHat ES 6 and 7 include the vulnerable code as they backported some of the 4.9 networking code into their kernels
- An attacker should not be able to exploit this vulnerability using a spoofed IP address. The attacker needs to first establish a TCP connection which is very difficult with a spoofed address.
- It is not known how much traffic the attacker will have to send. But likely not more than a user would send in a normal TCP connection.
- The attack can be launched against any exposed TCP service (Web, Mail, DNS...)
- The vulnerable functions, tcp_collapse_ofo_queue() and tcp_prune_ofo_queue(), are used to deal with reassembling TCP segments. This likely implies that an exploit would use many out of order or otherwise abnormal packets. But this is just a guess at this point.
- If you are vulnerable, your best bet is to update. There is likely not much else you can do (e.g. firewall rules)
You can find more details here: https://www.kb.cert.org/vuls/id/962459
---
Johannes B. Ullrich, Ph.D., Dean of Research, [SANS Technology Institute](https://sans.edu)
[Twitter](https://jbu.me/164)|
Keywords:
[3 comment(s)](https://isc.sans.edu/diary/What+Do+I+Need+To+Know+about+SegmentSmack/23964/#comments)
Click
[HERE](https://www.sans.org/profiles/dr-johannes-ullrich)to learn more about classes Johannes is teaching for SANS
×
![modal content]()
[Diary Archives](https://isc.sans.edu/diaryarchive.html)
## Comments
## Anonymous
## Aug 8th 2018
8 years ago
## Anonymous
## Aug 10th 2018
8 years ago
## Anonymous
## Aug 28th 2018
8 years ago