CVE-2018-5390: Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can lead to a denial of service
A flaw named SegmentSmack was found in the way the Linux kernel handled specially crafted TCP packets. A remote attacker could use this flaw to trigger time and calculation expensive calls to tcpcollapseofoqueue() and tcppruneofoqueue() functions by sending specially modified packets within ongoing TCP sessions which could lead to a CPU saturation and hence a denial of service on the system. Maintaining the denial of service condition requires continuous two-way TCP sessions to a reachable open port, thus the attacks cannot be performed using spoofed IP addresses.
Other sources
Linux kernel versions 4.9+ can be forced to make very expensive calls to tcpcollapseofoqueue() and tcppruneofoqueue() for every incoming packet which can lead to a denial of service.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:2.6.32-754.3.5.el6 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:2.6.32-358.93.1.el6 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:2.6.32-431.93.2.el6 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:2.6.32-504.76.2.el6 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:2.6.32-573.62.1.el6 - Upgrade
Upgrade
redhat/kernel-rtto a version that resolves this vulnerability.Fixed in 0:3.10.0-862.11.6.rt56.819.el7 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:3.10.0-862.11.6.el7 - Upgrade
Upgrade
redhat/kernel-altto a version that resolves this vulnerability.Fixed in 0:4.14.0-115.el7a - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:3.10.0-327.73.1.el7 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:3.10.0-514.58.1.el7 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:3.10.0-693.39.1.el7 - Upgrade
Upgrade
redhat/kernel-rtto a version that resolves this vulnerability.Fixed in 1:3.10.0-693.39.1.rt56.629.el6 - Upgrade
Upgrade
redhat/redhat-release-virtualization-hostto a version that resolves this vulnerability.Fixed in 0:4.2-5.2.el7 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.262-1Fixed in 6.1.176-1Fixed in 6.1.180-1Fixed in 6.12.94-1Fixed in 6.12.101-1Fixed in 7.1.7-1Fixed in 7.1.8-1 - Upgrade
Upgrade
Linux kernelto a version that resolves this vulnerability.Patch 3d4bf93ac12003f9b8e1e2de37fe27983deebdcf - Upgrade
Upgrade
Linux kernelto a version that resolves this vulnerability.Patch 58152ecbbcc6a0ce7fddd5bf5f6ee535834ece0c - Upgrade
Upgrade
Linux kernelto a version that resolves this vulnerability.Patch 72cd43ba64fc172a443410ce01645895850844c8 - Upgrade
Upgrade
Linux kernelto a version that resolves this vulnerability.Patch 8541b21e781a22dce52a74fef0b9bed00404a1cd - Upgrade
Upgrade
Linux kernelto a version that resolves this vulnerability.Patch f4a3313d8e2ca9fd8d8f45e40a2903ba782607e7
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2018-5390?
CVE-2018-5390 has been classified with a CVSS score indicating a high severity, as it allows attackers to potentially impact system performance.
How do I fix CVE-2018-5390?
To fix CVE-2018-5390, apply the appropriate kernel updates provided by your Linux distribution, specifically versions listed in the vulnerability advisory.
Which systems are affected by CVE-2018-5390?
CVE-2018-5390 affects specific versions of the Linux kernel, including Red Hat and Debian distributions as well as various Linux-based systems.
What are the potential impacts of exploiting CVE-2018-5390?
Exploiting CVE-2018-5390 could lead to denial-of-service conditions on affected systems due to excessive resource consumption.
Is there a known exploit for CVE-2018-5390?
Yes, CVE-2018-5390 has known exploit methods that enable attackers to craft malicious TCP packets to exploit the vulnerability.