vulnerability tcp RFC 5961 of linux kernel since v3.2 [released]
Hello all
I Don't know if a lots of people already aware about it. Seems not to be after tjc research
shortly on the usenix security conference was reported from a vulnerability on the TCP Protocol RFC 5961.
As i understand This Version is already implemented into the Linux Kernel since V3.6 but not in windows and ios.
this leak give the possibility to someone making an attack of type man in the middle.
Here is a link with more precision:
https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-5696
Seems that already a lot's a people tracked the leak and have a patch for it...
Now comes the question:
Jolla is able to update the kernel? if the patch is ready, that would be nice to have it.
One possible workaround has appeared. But may be a workaround a good and certified alternative?
Edit 04.05.2018: Fix is still not done for JP1
When may we expect to have it in our precious one? Does jolla may give a short word about it from their plan?
Have a nice sail
Workaround:
create (as root) the file /etc/sysctl.d/rfc5961.conf:
and reboot. If you do not want to reboot:
cy8aer ( 2016-08-19 13:20:39 +0200 )edit@cy8aer seems to be completely different as what what we can see by all patches referenced on the above link.
cemoi71 ( 2016-08-19 15:11:29 +0200 )editi'm definitively not skilled on the business, so that it makes me more cautious about it.
Sorry
i prefer wait for explanation and confirmation.
And official reaction/bugfix etc.. would help for sure.
Not that i want to ignore your solution and help. I'm just really cautious with this.
Maybe you could convert your remark as answer. That would help by this process of confirmation, explanation (6 validation). Anyway, many thanks for your fast answer.
@cemoi71: This was my source http://www.heise.de/forum/heise-Security/News-Kommentare/HTTP-Verbindungen-von-einer-Milliarde-Android-Geraeten-angreifbar/Workaround/posting-29072121/show/ - but german
cy8aer ( 2016-08-20 23:11:53 +0200 )edit@cy8aer i can read it, no problem. and like the author notified, that is a workaround, and not the final and well done solution....
cemoi71 ( 2016-09-01 16:36:51 +0200 )editHope that jolla will close the leak when the solution will be provided...
@cemoi71 it is not yet released in kernel-adaptation-sbj-3.4.108.20171017.1 (jolla1 2.1.3.7) and I doubt it is in 2.1.4.15.
lpr ( 2018-05-03 17:44:27 +0200 )edit