Patches now available to prevent DoS attack on Linux systems.
Denial-of-service attacks aren't just about external floods: A new US-CERT vulnerability note is a reminder that operating system kernel services can be used to effectively launch a DoS campaign against a system.
Vulnerability Note VU#962459 warns of a vulnerability in Linux kernels versions 4.9 and greater that can allow an attacker to overwhelm a network's resources with low-effort calls. With the right trigger, a Linux system can be forced to make a sequence of kernel calls for every packet – kernel calls that are hugely expensive in terms of system resources. There are limitations on the conditions, but the proof of the vulnerability exists.
Patches for the vulnerability are available for immediate application.
About the Author(s)
You May Also Like
Beyond Spam Filters and Firewalls: Preventing Business Email Compromises in the Modern Enterprise
April 30, 2024Key Findings from the State of AppSec Report 2024
May 7, 2024Is AI Identifying Threats to Your Network?
May 14, 2024Where and Why Threat Intelligence Makes Sense for Your Enterprise Security Strategy
May 15, 2024Safeguarding Political Campaigns: Defending Against Mass Phishing Attacks
May 16, 2024
Black Hat USA - August 3-8 - Learn More
August 3, 2024Cybersecurity's Hottest New Technologies: What You Need To Know
March 21, 2024