Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9q38-5hh6-p5gw

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

Reuven Plevinsky and Tal Vainshtein of Check Point Software Technologies Ltd. discovered that OpenBSD kernel (all versions, including 6.5) can be forced to create long chains of TCP SACK holes that cause very expensive calls to tcp_sack_option() for every incoming SACK packet which can lead to a denial of service.

Reuven Plevinsky and Tal Vainshtein of Check Point Software Technologies Ltd. discovered that OpenBSD kernel (all versions, including 6.5) can be forced to create long chains of TCP SACK holes that cause very expensive calls to tcp_sack_option() for every incoming SACK packet which can lead to a denial of service.

EPSS

Процентиль: 71%
0.00688
Низкий

7.5 High

CVSS3

Дефекты

CWE-1049

Связанные уязвимости

CVSS3: 7.5
nvd
больше 6 лет назад

OpenBSD kernel version <= 6.5 can be forced to create long chains of TCP SACK holes that causes very expensive calls to tcp_sack_option() for every incoming SACK packet which can lead to a denial of service.

CVSS3: 7.5
fstec
больше 6 лет назад

Уязвимость функции tcp_sack_option () ядра операционной системы OpenBSD, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 71%
0.00688
Низкий

7.5 High

CVSS3

Дефекты

CWE-1049