3 ms·
AWS Bulletin: https://aws.amazon.com/security/security-bulletins/AWS-2019-005/ https://aws.amazon.com/security/security-bulletins/AWS-2019-... FYI if your inst
by talawahtech 7y ago
AWS Bulletin: https://aws.amazon.com/security/security-bulletins/AWS-2019-005/ https://aws.amazon.com/security/security-bulletins/AWS-2019-...
FYI if your instances are behind an Application Load Balancer or Classic Load Balancer then they are protected, but NOT if they are behind a Network Load Balancer.
A patched kernel is available for Amazon Linux 1 and 2, so you won't have to disable SACK. You can run "sudo yum update kernel" to get it, but of course you have to reboot. Updated AMIs are also available.
Amazon Linux 1: https://alas.aws.amazon.com/ALAS-2019-1222.html https://alas.aws.amazon.com/ALAS-2019-1222.html
Amazon Linux 2: https://alas.aws.amazon.com/AL2/ALAS-2019-1222.html https://alas.aws.amazon.com/AL2/ALAS-2019-1222.html
For Amazon Linux 2 the fixed kernel is kernel-4.14.123-111.109.amzn2. Looking at my instances, it look like I have been on that version since Friday.
- ones_and_zeros 7y agoEven if your instances are behind ALBs or ELBs they may not be protected if they make outbound connections to the internet.
- pferde 7y agoIs this so? Can this kernel panic also be triggered in TCP connections initiated by the victim? I can't find a conclusive mention of this anywhere. As each direction of a TCP connection has its own MSS, it would make sense that an attacker's server could exploit this.
- dsp 7y agoThis is so. Both passive and active connections are at risk.