mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* question regarding BSD Security Advisory
@ 2004-03-03 21:50 GCS
  0 siblings, 0 replies; only message in thread
From: GCS @ 2004-03-03 21:50 UTC (permalink / raw)
  To: linux-kernel

Hi,

 I was asked if something like this vulnerability may exists in Linux,
or if is there any precautions for this?
"
Topic: many out-of-sequence TCP packets denial-of-service

I. Background

The Transmission Control Protocol (TCP) of the TCP/IP protocol suite
provides a connection-oriented, reliable, sequence-preserving data
stream service. When network packets making up a TCP stream (``TCP
segments'') are received out-of-sequence, they are maintained in a
reassembly queue by the destination system until they can be re-ordered
and re-assembled.

II. Problem Description

FreeBSD does not limit the number of TCP segments that may be held in a
reassembly queue.

III. Impact

A remote attacker may conduct a low-bandwidth denial-of-service attack
against a machine providing services based on TCP (there are many such
services, including HTTP, SMTP, and FTP). By sending many
out-of-sequence TCP segments, the attacker can cause the target machine
to consume all available memory buffers (``mbufs''), likely leading to
a system crash.
"

Cheers,
GCS

^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2004-03-03 22:08 UTC | newest]

Thread overview: (only message) (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2004-03-03 21:50 question regarding BSD Security Advisory GCS

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®