Skip to content

Commit 275b583

Browse files
qiluo-msftlguohan
authored andcommitted
Mitigate CVE-2018-5391 by sysctl (#1948)
Signed-off-by: Qi Luo <[email protected]>
1 parent cd8f6c8 commit 275b583

File tree

1 file changed

+4
-0
lines changed

1 file changed

+4
-0
lines changed

build_debian.sh

+4
Original file line numberDiff line numberDiff line change
@@ -272,6 +272,7 @@ check system $HOST
272272
EOF
273273

274274
## Config sysctl
275+
## TODO: ipfrag* are for mitigating CVE-2018-5391, remove after kernel upgraded
275276
sudo mkdir -p $FILESYSTEM_ROOT/var/core
276277
sudo augtool --autosave "
277278
set /files/etc/sysctl.conf/kernel.core_pattern '|/usr/bin/coredump-compress %e %t %p'
@@ -309,6 +310,9 @@ set /files/etc/sysctl.conf/net.ipv6.conf.eth0.accept_ra_defrtr 0
309310
310311
set /files/etc/sysctl.conf/net.core.rmem_max 2097152
311312
set /files/etc/sysctl.conf/net.core.wmem_max 2097152
313+
314+
set /files/etc/sysctl.conf/net.ipv4.ipfrag_high_thresh 262144
315+
set /files/etc/sysctl.conf/net.ipv4.ipfrag_low_thresh 196608
312316
" -r $FILESYSTEM_ROOT
313317

314318
## docker-py is needed by Ansible docker module

0 commit comments

Comments
 (0)