🚨 ⚠️ ⚠️ ⚠️
Urgent Linux advisory
⚠️ ⚠️ ⚠️ 🚨


Urgently run the following:

echo 0 | sudo tee /proc/sys/net/ipv4/tcp_sack

On all Linux hosts to work around the issue and then start patching your kernels

@sir just as not to run what I don't entirely understand: what will this change on my system/will it break my production?


@ignaloidas this will disable TCP SACK, an optional feature without which lossy connections may suffer reduced throughput

Without disabling this, your server can be remotely kernel paniced

