VMware begins patching process for Linux SACK vulnerabilities
scmagazineuk | July 04, 2019
VMware is instructing users to be on the lookout for software patches for 31 products that are affected by two vulnerabilities associated with the Linux kernel implementation of TCP Selective Acknowledgement .The two flaws, SACK Panic and SACK Excess Resource Usage, were originally found and disclosed by Netflix researchers, along with two Linux bugs.
These issues may allow a malicious entity to execute a denial of service attack against affected products, warns a July 2 company security advisory that collectively rates the vulnerabilities as important in severity. Panic has a base score of 7.5, while SACK Excess Resource Usage has a score of 5.3.