Уровень 0 · материалов: 3
В кластер входят документы об уязвимостях, приводящих к отказу в обслуживании или системному сбою, и не входят документы о других типах киберугроз или ошибок.
Общие признаки: отказ в обслуживании (DoS), исчерпание ресурсов системы, критические сбои и зависания
Группа выше: DDoS-атаки и защита от них
Смысл: The text describes a local Denial of Service (DoS) vulnerability in various Unix-like kernels (Linux and BSD) where an unprivileged user can crash the system or cause a kernel panic by exhausting file descriptors and CPU resources using a specific socket-based code loop.
A technical report on a local vulnerability in Linux and BSD kernels that allows unprivileged users to trigger a system crash or Denial of Service through resource exhaustion.
Смысл: The text reports a potential vulnerability in the Windows TCP/IP stack where a malformed FIN ACK packet can cause a server to hang onto socket resources indefinitely, potentially enabling a Denial of Service (DDoS) attack through resource exhaustion.
A bug in the Windows TCP implementation allows a client to keep server sockets open indefinitely by sending incorrect sequence numbers during connection closure.
Смысл: The main idea is that a hardware-level flaw in AMD Ryzen CPUs allows specific FMA3 instructions to crash the entire system, which, while harmless for general performance, creates a security vulnerability for DoS attacks that AMD plans to fix via BIOS/AGESA updates.
AMD Ryzen processors have an FMA3 instruction bug that can cause total system freezes and potentially allow DoS attacks, but it is fixable via a BIOS update.