Netflix discovers SACK Panic and other Linux security flaws

Netflix security team discovers the new “SACK” Panic security vulnerability.

The Netflix security team discovered these flaws during routine security testing work. They are triggered by sending a series of malicious packets to vulnerable systems. The result can slow or crash the target system – effectively triggering a remote Kernel panic.

Major vendors have released a series of patches and workarounds.

The three vulnerabilities are:

AWS has also issued an advisory for its cloud customers.

More details are available in the security advisory posted on GitHubRed HatSUSE and Debian also have helpful resources and information.

