Vulnerability Note VU#962459

Linux Kernel TCP implementation vulnerable to Denial of Service

Original Release date: 06 Aug 2018 | Last revised: 06 Aug 2018

Overview

The Linux kernel, versions 4.9+, is vulnerable to denial of service conditions with low rates of specially modified packets.

Description

CWE-400: Uncontrolled Resource Consumption ('Resource Exhaustion') - CVE-2018-5390

Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can lead to a denial of service. An attacker can induce a denial of service condition by sending specially modified packets within ongoing TCP sessions. Maintaining the denial of service condition requires continuous two-way TCP sessions to a reachable open port. Thus, the attacks cannot be performed using spoofed IP addresses.

Impact

An remote attacker may be able to trigger a denial-of-service condition against a system with an available open port.

Solution

Apply a patch
Patches for the Linux kernel are available to address the vulnerability.

Vendor Information (Learn More)

VendorStatusDate NotifiedDate Updated
3com IncUnknown23 Jul 201823 Jul 2018
A10 NetworksUnknown27 Jul 201827 Jul 2018
ACCESSUnknown23 Jul 201823 Jul 2018
Actelis NetworksUnknown27 Jul 201827 Jul 2018
ActiontecUnknown23 Jul 201823 Jul 2018
ADTRANUnknown23 Jul 201823 Jul 2018
aep NETWORKSUnknown23 Jul 201823 Jul 2018
AerohiveUnknown23 Jul 201823 Jul 2018
AhnLab IncUnknown27 Jul 201827 Jul 2018
AirWatchUnknown23 Jul 201823 Jul 2018
Akamai Technologies, Inc.Unknown27 Jul 201827 Jul 2018
Alcatel-Lucent EnterpriseUnknown23 Jul 201823 Jul 2018
AmazonUnknown23 Jul 201823 Jul 2018
Android Open Source ProjectUnknown23 Jul 201823 Jul 2018
ANTlabsUnknown23 Jul 201823 Jul 2018
If you are a vendor and your product is affected, let us know.View More »

CVSS Metrics (Learn More)

Group Score Vector
Base 7.1 AV:N/AC:M/Au:N/C:N/I:N/A:C
Temporal 6.4 E:POC/RL:ND/RC:C
Environmental 6.4 CDP:ND/TD:H/CR:ND/IR:ND/AR:ND

References

Credit

Thanks to Juha-Matti Tilli (Aalto University, Department of Communications and Networking / Nokia Bell Labs) for reporting this vulnerability.

This document was written by Trent Novelly.

Other Information

  • CVE IDs: CVE-2018-5390
  • Date Public: 23 Jul 2018
  • Date First Published: 06 Aug 2018
  • Date Last Updated: 06 Aug 2018
  • Document Revision: 17

Feedback

If you have feedback, comments, or additional information about this vulnerability, please send us email.