Linux Kernel 'tcp_input.c' Remote Denial of Service Vulnerability
BID:104976
CVE-2018-5390 |Info
Linux Kernel 'tcp_input.c' Remote Denial of Service Vulnerability
| Bugtraq ID: | 104976 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2018-5390 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 06 2018 12:00AM |
| Updated: | Feb 13 2019 01:00PM |
| Credit: | Juha-Matti Tilli |
| Vulnerable: |
Redhat Enterprise Mrg 2 Redhat Enterprise Linux 7 Redhat Enterprise Linux 6 Redhat Enterprise Linux 5 Oracle Communications Session Border Controller SCz8.1.0 Oracle Communications Session Border Controller SCz8.0.0 Oracle Communications Session Border Controller SCz7.4.1 Oracle Communications Session Border Controller SCZ7.4.0 Linux kernel 4.17.3 Linux kernel 4.17.2 Linux kernel 4.17.1 Linux kernel 4.16.11 Linux kernel 4.16.9 Linux kernel 4.16.6 Linux kernel 4.16.3 Linux kernel 4.15.14 Linux kernel 4.15.11 Linux kernel 4.15.9 Linux kernel 4.15.4 Linux kernel 4.14.31 Linux kernel 4.14.13 Linux kernel 4.14.11 Linux kernel 4.14.10 Linux kernel 4.14.6 Linux kernel 4.14.5 Linux kernel 4.14.1 Linux kernel 4.13.11 Linux kernel 4.13.10 Linux kernel 4.13.9 Linux kernel 4.13.8 Linux kernel 4.13.7 Linux kernel 4.13.6 Linux kernel 4.13.4 Linux kernel 4.13.3 Linux kernel 4.12.9 Linux kernel 4.12.4 Linux kernel 4.12.3 Linux kernel 4.12.2 Linux kernel 4.11.9 Linux kernel 4.11.5 Linux kernel 4.11.4 Linux kernel 4.11.3 Linux kernel 4.11.2 Linux kernel 4.11.1 Linux kernel 4.11 Linux kernel 4.10.15 Linux kernel 4.10.13 Linux kernel 4.10.12 Linux kernel 4.10.10 Linux kernel 4.10.6 Linux kernel 4.10.4 Linux kernel 4.10 Linux kernel 4.9.13 Linux kernel 4.9.8 Linux kernel 4.9.4 Linux kernel 4.9.3 Linux kernel 4.9.9 Linux kernel 4.9.11 Linux kernel 4.9 Linux kernel 4.17.4 Linux kernel 4.17.11 Linux kernel 4.17.10 Linux kernel 4.17-rc2 Linux kernel 4.17 Linux kernel 4.16-rc7 Linux kernel 4.16-rc6 Linux kernel 4.16-rc Linux kernel 4.16 Linux kernel 4.15.8 Linux kernel 4.15.7 Linux kernel 4.15.16 Linux kernel 4.15-rc5 Linux kernel 4.15 Linux kernel 4.14.8 Linux kernel 4.14.7 Linux kernel 4.14.4 Linux kernel 4.14.3 Linux kernel 4.14.2 Linux kernel 4.14.15 Linux kernel 4.14.14 Linux kernel 4.14.0-rc1 Linux kernel 4.14-rc5 Linux kernel 4.14-rc1 Linux kernel 4.14 Linux kernel 4.13.5 Linux kernel 4.13.2 Linux kernel 4.13.1 Linux kernel 4.13-rc1 Linux kernel 4.13 Linux kernel 4.12.10 Linux kernel 4.12.1 Linux kernel 4.12-rc1 Linux kernel 4.12 Linux kernel 4.11.8 Linux kernel 4.11.7 Linux kernel 4.10.9 Linux kernel 4.10.8 Linux kernel 4.10.7 Linux kernel 4.10.5 Linux kernel 4.10.3 Linux kernel 4.10.2 Linux kernel 4.10.11 Linux kernel 4.10.1 Juniper vSRX Series 0 Juniper Vmx - Juniper QFX5200 0 Juniper QFX5100 0 Juniper QFX10008 0 Juniper PTX10008 0 Juniper NFX 250 0 Juniper NFX 150 0 Juniper MX80 0 Juniper MX480 0 Citrix Receiver for Linux 0 Citrix Linux Virtual Desktop 0 |
| Not Vulnerable: | |
Discussion
Linux Kernel 'tcp_input.c' Remote Denial of Service Vulnerability
Linux Kernel is prone to a remote denial-of-service vulnerability.
An attacker can exploit this issue to cause a denial-of-service condition.
Linux kernel 4.9 and later are vulnerable.
Linux Kernel is prone to a remote denial-of-service vulnerability.
An attacker can exploit this issue to cause a denial-of-service condition.
Linux kernel 4.9 and later are vulnerable.
Exploit / POC
Linux Kernel 'tcp_input.c' Remote Denial of Service Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Linux Kernel 'tcp_input.c' Remote Denial of Service Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Linux Kernel 'tcp_input.c' Remote Denial of Service Vulnerability
References:
References:
- Linux kernel Homepage (kernel.org)
- [PATCH net 0/5] tcp: more robust ooo handling (Spincs)
- Bug 1601704 CVE-2018-5390 kernel: TCP segments with random offsets (Redhat)
- Citrix Security Advisory for TCP Reassembly Resource Exhaustion (Citrix)
- CVE-2018-5390 (Redhat)
- Information about SegmentSmack findings (PAN-SA-2018-0013) (Palo Alto Networks)
- Junos platforms vulnerable to SegmentSmack attack [VU#962459] (Juniper Networks)
- Oracle Critical Patch Update Advisory - January 2019 (Oracle)
- VU#962459 Linux Kernel TCP implementation vulnerable to Denial of Service (CERT)