← Back

CVE-2018-6922

nvd nist
Published: Aug 9, 2018Modified: Nov 21, 2024

JSON object

Loading...
5.3
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

One of the data structures that holds TCP segments in all versions of FreeBSD prior to 11.2-RELEASE-p1, 11.1-RELEASE-p12, and 10.4-RELEASE-p10 uses an inefficient algorithm to reassemble the data. This causes the CPU time spent on segment processing to grow linearly with the number of segments in the reassembly queue. An attacker who has the ability to send TCP traffic to a victim system can degrade the victim system's network performance and/or consume excessive CPU by exploiting the inefficiency of TCP reassembly handling, with relatively small bandwidth cost.

Affected (19)

Products: Freebsd: Freebsd
1 product
Freebsd
Configuration A
19 vulnerable
Vulnerable SoftwareAffected Versions
Freebsd
Version 10.4
Version 10.4 p1
Version 10.4 p3
Version 10.4 p4
Version 10.4 p5
Version 10.4 p6
Version 10.4 p7
Version 10.4 p8
Version 10.4 p9
Version 11.1
Version 11.1 p11
Version 11.1 p1
Version 11.1 p2
Version 11.1 p4
Version 11.1 p5
Version 11.1 p6
Version 11.1 p7
Version 11.1 p9
Version 11.2

References (10)

Source: secteam@freebsd.org
Third Party AdvisoryVDB Entry
Source: secteam@freebsd.org
Third Party AdvisoryVDB Entry
Source: secteam@freebsd.org
Third Party Advisory
Source: secteam@freebsd.org
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.