Linux Kernel TCP RTO Calculation Denial of Service
by Carol~
- 2/22/10 8:43 AM
In Reply to: VULNERABILITIES \ FIXES - February 22, 2010 by Carol~
Release Date : 2010-02-22
Criticality level : Less critical
Impact : DoS
Where : From remote
Solution Status : Vendor Workaround
Operating System : Linux Kernel 2.6.x
Description :
A vulnerability has been reported in the Linux kernel, which can be exploited by malicious people to cause a DoS (Denial of Service).
The vulnerability is caused due to an error when calculating retransmission timeouts (RTO), which can be exploited to e.g. cause a high CPU and network load on an affected system.
Successful exploitation may require that TCP timestamps are disabled.
The vulnerability is reported in the 2.6.32.x kernel tree.
Solution :
Fixed in the GIT repository.
Original Advisory :
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=598856407d4e20ebb4de01a91a93d89325924d43
http://secunia.com/advisories/38594/

Moderator
CNET Staff
Samsung Staff
Dell Staff