From b8c7d1492ce1ffe18ef96a5909cbcf4cdc96615b Mon Sep 17 00:00:00 2001 From: nicoo Date: Mon, 17 Jun 2019 17:04:15 -0400 Subject: [PATCH] ansible/base: Workaround [NFLX-2019-001] (CVE-2019-1147{7,8,9}) Disable Selective Acknowledgement (SACK) [NFLX-2019-001]: https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-001.md --- ansible/roles/base/tasks/06net.yml | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/ansible/roles/base/tasks/06net.yml b/ansible/roles/base/tasks/06net.yml index 04e33cd..e257b9b 100644 --- a/ansible/roles/base/tasks/06net.yml +++ b/ansible/roles/base/tasks/06net.yml @@ -24,5 +24,10 @@ # C.f. https://queue.acm.org/detail.cfm?id=3022184 net.ipv4.tcp_congestion_control: bbr + # Disable Selective Acknowledgement (SACK) + # Workaround CVE-2019-11477, CVE-2019-11478, CVE-2019-11479 + # See https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-001.md + net.ipv4.tcp_sack: 0 + loop_control: label: "{{ item.key }}" -- 1.7.10.4