CVE-2018-5390

HIGH

Linux kernel <4.9 - DoS

Title source: llm
STIX 2.1

Description

Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can lead to a denial of service.

References (42)

Core 42
Core References
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2018:2785
Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert-vn
https://www.kb.cert.org/vuls/id/962459
Third Party Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/3741-2/
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2018:2776
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2018:2933
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2018:2403
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2018:2395
Third Party Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/3763-1/
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2018:2384
Third Party Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/3741-1/
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2018:2402
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2018:2948
Third Party Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/3742-2/
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1041434
Third Party Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/3732-2/
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/104976
Third Party Advisory mailing-list x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2018/08/msg00014.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1041424
Third Party Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/3742-1/
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2018:2924
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2018:2789
Third Party Advisory vendor-advisory x_refsource_debian
https://www.debian.org/security/2018/dsa-4266
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2018:2645
Third Party Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/3732-1/
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2018:2791
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2018:2790
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2019/06/28/2
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2019/07/06/3
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2019/07/06/4
Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpujul2020.html
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20180815-0003/
Third Party Advisory x_refsource_confirm
http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2018-004.txt
Third Party Advisory x_refsource_confirm
https://www.synology.com/support/security/Synology_SA_18_41
Third Party Advisory x_refsource_confirm
https://support.f5.com/csp/article/K95343321
Third Party Advisory x_refsource_confirm
https://cert-portal.siemens.com/productcert/pdf/ssa-377115.pdf

Scores

CVSS v3 7.5
EPSS 0.1060
EPSS Percentile 93.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-400
Status published
Products (46)
a10networks/advanced_core_operating_system 3.2.2 (2 CPE variants)
a10networks/advanced_core_operating_system 4.1.0 (2 CPE variants)
a10networks/advanced_core_operating_system 4.1.1 p8
a10networks/advanced_core_operating_system 4.1.2 (2 CPE variants)
a10networks/advanced_core_operating_system 4.1.4 (2 CPE variants)
canonical/ubuntu_linux 12.04
canonical/ubuntu_linux 14.04
canonical/ubuntu_linux 16.04
canonical/ubuntu_linux 18.04
cisco/collaboration_meeting_rooms 1.0
... and 36 more
Published Aug 06, 2018
Tracked Since Feb 18, 2026