Security Vulnerability in the Solaris 10 TCP Fusion Code May Lead to a System Panic, Resulting in a Denial of Service (DoS)



Category :Security
Release Phase :Resolved
Product :Solaris 10 Operating System  
Bug Id :6348581  
Date of Resolved Release :17-OCT-2006 


Impact

Solaris 10 systems may panic in the tcp_fuse_rcv_drain() TCP/IP function when using TCP loopback connections, where both ends of the connection are on the same system. This may allow a local unprivileged user to cause a Denial of Service (DoS) condition on the affected host.


Contributing Factors

This issue can occur in the following releases:

SPARC Platform

x86 Platform

Note: Solaris 8 and Solaris 9 are not impacted by this issue.


Symptoms

A system panic in tcp_fuse_rcv_drain() TCP/IP function is representative of this issue.


Workaround

To work around the described issue until patches can be installed, disable TCP Fusion by adding the following line to the "/etc/system" file and rebooting the system:

    set ip:do_tcp_fusion = 0x0

Undo the above change to the "/etc/system" file and reboot to re-enable TCP Fusion.

Note: The workaround option above may affect performance.


Resolution

This issue is addressed in the following releases:

SPARC Platform

x86 Platform






Attachments
This solution has no attachment

 
 
Login Required

You must login and have a valid contract to access Sun's Premium content which includes:

  • Sun Alerts
  • Bugs
  • Patches
  • Solutions
  • White Papers
  • Documentation
  • Support Knowledge

Login Required

You must login and have a valid contract to access Sun's contracted features

Access Legend:

(Login to access)   Sun Contracted Content
(Login to access)   Sun Contracted Feature

Please make use of SunSolve Feedback application by selecting the floating [+] to provide feedback about this specific document.

Search

Article Details
Article ID : 200878
Article Type : Sun Alert
Last reviewed : 2006-10-17
Audience : PUBLIC
Keywords :
Provide feedback  (help)
Page Tools
»  Print This Page
»  Email This Article
»  Bookmark This Article