Lucene search

K
archlinuxArch LinuxASA-201608-13
HistoryAug 14, 2016 - 12:00 a.m.

linux-grsec: information disclosure

2016-08-1400:00:00
Arch Linux
lists.archlinux.org
31

0.004 Low

EPSS

Percentile

75.1%

A security issue has been found in the Linux kernel’s implementation of
challenge ACKs as specified in RFC 5961. An attacker which knows a
connection’s client IP, server IP and server port can abuse the
challenge ACK mechanism to determine the accuracy of a normally β€˜blind’
attack on the client or server.

Successful exploitation of this flaw could allow a remote attacker to
inject or control a TCP stream contents in a connection between a Linux
device and its connected client/server.

OSVersionArchitecturePackageVersionFilename
anyanyanylinux-grsec<Β 4.7.201608131240-1UNKNOWN