TCP SACK (CVE-2019-5599)

hiren hiren at strugglingcoder.info
Tue Jun 18 14:57:19 UTC 2019


On 06/18/19 at 10:33P, mike tancsa wrote:
> Hi all,
> With respect to the bugs describe in
> https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-001.md
> *<quote>
>       SACK Slowness (FreeBSD 12 using the RACK TCP Stack)
[snip]
> 
> *</quote>*
> 
> *How does I know if this is enabled in my default kernel on RELENG_12 ?
> There is some vague mention in various forums this is not the default on
> FreeBSD ? Can anyone shed more light as to how this does/does not impact
> FreeBSD ?

RACK is one of the tcp stacks ($src/sys/netinet/tcp_stacks) and not
enabled by default.

So, by default, FreeBSD is not affected, afaict. This advisory is for
when you do use RACK.

Cheers,
Hiren
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 618 bytes
Desc: not available
URL: <http://lists.freebsd.org/pipermail/freebsd-security/attachments/20190618/0e3190fd/attachment.sig>


More information about the freebsd-security mailing list