VulnerabilityModified
CVE-2018-5390
Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can lead to a denial of service.
HIGH 7.5EPSS 73.7%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 73.7%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can lead to a denial of service.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 73.72% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-400
- Affected
- redhat/virtualization · redhat/enterprise linux desktop · redhat/enterprise linux server · redhat/enterprise linux server aus · redhat/enterprise linux server eus · redhat/enterprise linux server tus · redhat/enterprise linux workstation · linux/linux kernel · canonical/ubuntu linux · debian/debian linux · hp/aruba airwave amp · hp/aruba clearpass policy manager · f5/big-ip access policy manager · f5/big-ip advanced firewall manager · f5/big-ip analytics · f5/big-ip application acceleration manager · f5/big-ip application security manager · f5/big-ip domain name system · f5/big-ip edge gateway · f5/big-ip fraud protection service · +18 more
- Source
- cret@cert.org
References
- http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2018-004.txtThird Party Advisory
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20181031-02-linux-enThird Party Advisory
- http://www.openwall.com/lists/oss-security/2019/06/28/2Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2019/07/06/3Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2019/07/06/4Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/104976Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041424Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041434Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:2384Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2395Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2402Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2403Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2645Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2776Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2785Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2789Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2790Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2791Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2924Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2933Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2948Third Party Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-377115.pdfThird Party Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/davem/net.git/commit/?id=1a4f14bab1868b443f0dd3c55b689a478f82e72ePatch, Vendor Advisory
- https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/08/msg00014.htmlThird Party Advisory
- https://security.netapp.com/advisory/ntap-20180815-0003/Third Party Advisory
- https://support.f5.com/csp/article/K95343321Third Party Advisory
- https://support.f5.com/csp/article/K95343321?utm_source=f5support&%3Butm_medium=RSS
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180824-linux-tcpThird Party Advisory
- https://usn.ubuntu.com/3732-1/Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.