CVE-2018-5390
high · 7.5Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can lead to a denial of service.
7.5
CVSS
73.7%
EPSS (exploit prob.)
99th
EPSS percentile
2018-08-06
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weaknesses
CWE-400
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| redhat | virtualization | 4.0 |
| redhat | enterprise_linux_desktop | 7.0 |
| redhat | enterprise_linux_server | 7.0 |
| redhat | enterprise_linux_server_aus | 6.4 |
| redhat | enterprise_linux_server_aus | 6.5 |
| redhat | enterprise_linux_server_aus | 6.6 |
| redhat | enterprise_linux_server_aus | 7.2 |
| redhat | enterprise_linux_server_aus | 7.3 |
| redhat | enterprise_linux_server_aus | 7.4 |
| redhat | enterprise_linux_server_eus | 6.4 |
| redhat | enterprise_linux_server_eus | 6.7 |
| redhat | enterprise_linux_server_eus | 7.2 |
| redhat | enterprise_linux_server_eus | 7.3 |
| redhat | enterprise_linux_server_eus | 7.4 |
| redhat | enterprise_linux_server_eus | 7.5 |
| redhat | enterprise_linux_server_tus | 6.6 |
| redhat | enterprise_linux_server_tus | 7.2 |
| redhat | enterprise_linux_server_tus | 7.3 |
| redhat | enterprise_linux_server_tus | 7.4 |
| redhat | enterprise_linux_workstation | 7.0 |
| linux | linux_kernel | >= 4.9, < 4.18 |
| linux | linux_kernel | 4.18 |
| linux | linux_kernel | 4.18 |
| linux | linux_kernel | 4.18 |
| linux | linux_kernel | 4.18 |
| linux | linux_kernel | 4.18 |
| linux | linux_kernel | 4.18 |
| canonical | ubuntu_linux | 12.04 |
| canonical | ubuntu_linux | 14.04 |
| canonical | ubuntu_linux | 16.04 |
| canonical | ubuntu_linux | 18.04 |
| debian | debian_linux | 8.0 |
| debian | debian_linux | 9.0 |
| hp | aruba_airwave_amp | < 8.2.7.1 |
| hp | aruba_clearpass_policy_manager | >= 6.6.0, <= 6.6.9 |
| hp | aruba_clearpass_policy_manager | >= 6.7.0, <= 6.7.5 |
| f5 | big-ip_access_policy_manager | >= 11.5.1, <= 11.6.3 |
| f5 | big-ip_access_policy_manager | >= 12.1.0, <= 12.1.3 |
| f5 | big-ip_access_policy_manager | >= 13.0.0, <= 13.1.1 |
| f5 | big-ip_access_policy_manager | 14.0.0 |
Check a specific version with /api/v1/cve/match.
References
- http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2018-004.txt
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20181031-02-linux-en
- http://www.openwall.com/lists/oss-security/2019/06/28/2
- http://www.openwall.com/lists/oss-security/2019/07/06/3
- http://www.openwall.com/lists/oss-security/2019/07/06/4
- http://www.securityfocus.com/bid/104976
- http://www.securitytracker.com/id/1041424
- http://www.securitytracker.com/id/1041434
- https://access.redhat.com/errata/RHSA-2018:2384
- https://access.redhat.com/errata/RHSA-2018:2395
- https://access.redhat.com/errata/RHSA-2018:2402
- https://access.redhat.com/errata/RHSA-2018:2403
- https://access.redhat.com/errata/RHSA-2018:2645
- https://access.redhat.com/errata/RHSA-2018:2776
- https://access.redhat.com/errata/RHSA-2018:2785
- https://access.redhat.com/errata/RHSA-2018:2789
- https://access.redhat.com/errata/RHSA-2018:2790
- https://access.redhat.com/errata/RHSA-2018:2791
- https://access.redhat.com/errata/RHSA-2018:2924
- https://access.redhat.com/errata/RHSA-2018:2933
- https://access.redhat.com/errata/RHSA-2018:2948
- https://cert-portal.siemens.com/productcert/pdf/ssa-377115.pdf
- https://git.kernel.org/pub/scm/linux/kernel/git/davem/net.git/commit/?id=1a4f14bab1868b443f0dd3c55b689a478f82e72e
- https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0
- https://lists.debian.org/debian-lts-announce/2018/08/msg00014.html
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2018-5390