CVE-2018-5390
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can lead to a denial of service.
Affected (125)
Products: Redhat: Enterprise Linux Desktop, Enterprise Linux Server, Enterprise Linux Server Aus, Enterprise Linux Server Eus, Enterprise Linux Server Tus, Enterprise Linux Workstation, Virtualization · Linux: Linux Kernel · Canonical: Ubuntu Linux · +5 more
Show all products
Redhat: Enterprise Linux Desktop, Enterprise Linux Server, Enterprise Linux Server Aus, Enterprise Linux Server Eus, Enterprise Linux Server Tus, Enterprise Linux Workstation, Virtualization · Linux: Linux Kernel · Canonical: Ubuntu Linux · Debian: Debian Linux · Hp: Aruba Airwave Amp, Aruba Clearpass Policy Manager · F5: Big Ip Access Policy Manager, Big Ip Advanced Firewall Manager, Big Ip Analytics, Big Ip Application Acceleration Manager, Big Ip Application Security Manager, Big Ip Domain Name System, Big Ip Edge Gateway, Big Ip Fraud Protection Service, Big Ip Global Traffic Manager, Big Ip Link Controller, Big Ip Local Traffic Manager, Big Ip Policy Enforcement Manager, Big Ip Webaccelerator, Traffix Systems Signaling Delivery Controller · A10networks: Advanced Core Operating System · Cisco: Collaboration Meeting Rooms, Digital Network Architecture Center, Expressway, Expressway Series, Meeting Management, Network Assurance Engine, Threat Grid Cloud, Webex Hybrid Data Security, Webex Video Mesh, Telepresence Video Communication Server Firmware, Telepresence Conductor Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 7.0 | |
| Version 7.0 | |
| Version 6.4 | |
| Version 6.4 | |
| Version 6.6 | |
| Version 7.0 | |
| Version 4.0 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From 4.9 to 4.18 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 12.04 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 8.0 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 8.2.7.1 | |
| From 6.6.0 to 6.6.9 |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.1 to 11.6.3 | |
| From 11.5.1 to 11.6.3 | |
| From 11.5.1 to 11.6.3 | |
| From 11.5.1 to 11.6.3 | |
| From 11.5.1 to 11.6.3 | |
| From 11.5.1 to 11.6.3 | |
| From 11.5.1. to 11.6.3 | |
| From 11.5.1 to 11.6.3 | |
| From 11.5.1 to 11.6.3 | |
| From 11.5.1 to 11.6.3 | |
| After 13.0.0 to 13.1.1 | |
| From 11.5.1 to 11.6.3 | |
| From 11.5.1 to 11.6.3 | |
| From 5.0.0 to 5.1.0 |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.2.2 |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.0 | |
| Version 1.2 | |
| Version x8.10.1 | |
| All versions | |
| Version 1.0.1 | |
| Version 2.1(1a) | |
| All versions | |
| All versions | |
| All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Version x8.10.1 |
| Running on/with | Platform Versions |
|---|---|
Cisco Telepresence Video Communication Server | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Version xc4.3.1 |
| Running on/with | Platform Versions |
|---|---|
Cisco Telepresence Conductor | All versions |
References (84)
Source: cret@cert.org
Third Party Advisory
Source: cret@cert.org
Third Party Advisory
Source: cret@cert.org
Mailing ListThird Party Advisory
Source: cret@cert.org
Mailing ListThird Party Advisory
Source: cret@cert.org
Mailing ListThird Party Advisory
Source: cret@cert.org
Third Party Advisory
Source: cret@cert.org
PatchVendor Advisory
Source: cret@cert.org
Third Party Advisory
Source: cret@cert.org
Third Party Advisory
Source: cret@cert.org
Source: cret@cert.org
Third Party Advisory
Source: cret@cert.org
MitigationThird Party Advisory
Source: cret@cert.org
Third Party AdvisoryUS Government Resource
Source: cret@cert.org
PatchThird Party Advisory
Source: cret@cert.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.