CVE-2017-5972
HIGHLinux Kernel < 3.19.8 - Denial of Service
Title source: ruleDescription
The TCP stack in the Linux kernel 3.x does not properly implement a SYN cookie protection mechanism for the case of a fast network connection, which allows remote attackers to cause a denial of service (CPU consumption) by sending many TCP SYN packets, as demonstrated by an attack against the kernel-3.10.0 package in CentOS Linux 7. NOTE: third parties have been unable to discern any relationship between the GitHub Engineering finding and the Trigemini.c attack code.
Exploits (1)
References (9)
Scores
CVSS v3
7.5
EPSS
0.1891
EPSS Percentile
95.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-400
Status
published
Products (1)
linux/linux_kernel
3.0.0 - 3.19.8
Published
Feb 14, 2017
Tracked Since
Feb 18, 2026