Network Security, Patch/Configuration Management, Vulnerability Management

VMware begins patching process for Linux SACK vulnerabilities

VMware is instructing users to be on the lookout for software patches for 31 products that are affected by two vulnerabilities associated with the Linux kernel implementation of TCP Selective Acknowledgement (SACK).

The two flaws, SACK Panic (CVE-2019-11477) and SACK Excess Resource Usage (CVE-2019-11478), were originally found and disclosed by Netflix researchers, along with two Linux bugs.

"These issues may allow a malicious entity to execute a denial of service attack against affected products, warns a July 2 company security advisory that collectively rates the vulnerabilities as important in severity. (SACK Panic has a CVSSv3 base score of 7.5, while SACK Excess Resource Usage has a score of 5.3.)

As of July 3, 11:30 a.m. ET, patches were available for SD-WAN Edge by VeloCloud, SD-WAN Gateway by VeloCloud, SD-WAN Orchestrator by VeloCloud, Unified Access Gateway and vCenter Server Appliance, and workarounds were available for Unified Access Gateway and vCloud Director for Service Providers.

Patches are pending for AppDefense, Container Service Extension, Enterprise PKS, Horizon, Horizon DaaS, Hybrid Cloud Extension, Identity Manager, Integrated OpenStack, NSX for vSphere, NSX-T Data Center, Pulse Console, Skyline Collector, vCloud Availability Appliance, vCloud Director For Service Providers, vCloud Usage Meter, vRealize Automation, vRealize Business for Cloud, vRealize Code Stream, vRealize Log Insight, vRealize Network Insight, vRealize Operations manager, vRealize Orchestrator Appliance, vRealize Suite Lifecycle Manager, vSphere Data Protection, vSphere Integrated Containers and vSphere Replication.

Bradley Barth

As director of multimedia content strategy at CyberRisk Alliance, Bradley Barth develops content for online conferences, webcasts, podcasts video/multimedia projects — often serving as moderator or host. For nearly six years, he wrote and reported for SC Media as deputy editor and, before that, senior reporter. He was previously a program executive with the tech-focused PR firm Voxus. Past journalistic experience includes stints as business editor at Executive Technology, a staff writer at New York Sportscene and a freelance journalist covering travel and entertainment. In his spare time, Bradley also writes screenplays.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms and Conditions and Privacy Policy.