First published: Mon Jul 30 2018(Updated: )
A flaw named FragmentSmack was found in the way the Linux kernel handled reassembly of fragmented IPv4 and IPv6 packets. A remote attacker could use this flaw to trigger time and calculation expensive fragment reassembly algorithms by sending specially crafted packets which could lead to a CPU saturation and hence a denial of service on the system. External References: <a href="https://access.redhat.com/articles/3553061">https://access.redhat.com/articles/3553061</a> <a href="https://www.kb.cert.org/vuls/id/641765">https://www.kb.cert.org/vuls/id/641765</a> A fix is a merge commit in the Linux kernel tree: <a href="https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=c30f1fc041b74ecdb072dd44f858750414b8b19f">https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=c30f1fc041b74ecdb072dd44f858750414b8b19f</a> consisting of the following commits: 7969e5c40dfd04799d4341f1b7cd266b6e47f227 385114dec8a49b5e5945e77ba7de6356106713f4 fa0f527358bd900ef92f925878ed6bfbd51305cc
Credit: cret@cert.org cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Linux kernel | >=3.9<=4.18 | |
Redhat Enterprise Linux Desktop | =6.0 | |
Redhat Enterprise Linux Desktop | =7.0 | |
Red Hat Enterprise Linux Server | =6.0 | |
Red Hat Enterprise Linux Server | =7.0 | |
Red Hat Enterprise Linux Server | =6.4 | |
Red Hat Enterprise Linux Server | =6.5 | |
Red Hat Enterprise Linux Server | =6.6 | |
Red Hat Enterprise Linux Server | =7.2 | |
Red Hat Enterprise Linux Server | =7.3 | |
Red Hat Enterprise Linux Server | =7.4 | |
Red Hat Enterprise Linux Server | =6.7 | |
Red Hat Enterprise Linux Server | =7.3 | |
Red Hat Enterprise Linux Server | =7.4 | |
Red Hat Enterprise Linux Server | =7.5 | |
Red Hat Enterprise Linux Server | =6.6 | |
Red Hat Enterprise Linux Server | =7.2 | |
Red Hat Enterprise Linux Server | =7.3 | |
Red Hat Enterprise Linux Server | =7.4 | |
Redhat Enterprise Linux Workstation | =6.0 | |
Redhat Enterprise Linux Workstation | =7.0 | |
Debian Debian Linux | =8.0 | |
Debian Debian Linux | =9.0 | |
Canonical Ubuntu Linux | =12.04 | |
Canonical Ubuntu Linux | =14.04 | |
Canonical Ubuntu Linux | =16.04 | |
Canonical Ubuntu Linux | =18.04 | |
Microsoft Windows 10 | ||
Microsoft Windows 10 | =1607 | |
Microsoft Windows 10 | =1703 | |
Microsoft Windows 10 | =1709 | |
Microsoft Windows 10 | =1803 | |
Microsoft Windows 7 | =sp1 | |
Microsoft Windows 8.1 | ||
Microsoft Windows RT 8.1 | ||
Microsoft Windows Server 2008 | =sp2 | |
Microsoft Windows Server 2008 | =r2-sp1 | |
Microsoft Windows Server 2008 Itanium | =r2-sp1 | |
Microsoft Windows Server 2012 | ||
Microsoft Windows Server 2012 | =r2 | |
Microsoft Windows Server 2016 | ||
Microsoft Windows Server 2016 | =1709 | |
Microsoft Windows Server 2016 | =1803 | |
F5 BIG-IP Access Policy Manager | >=11.5.1<11.6.5.1 | |
F5 BIG-IP Access Policy Manager | >=12.1.0<12.1.5 | |
F5 BIG-IP Access Policy Manager | >=13.0.0<13.1.3 | |
F5 BIG-IP Access Policy Manager | >=14.0.0<14.0.1.1 | |
F5 BIG-IP Access Policy Manager | >=14.1.0<14.1.2.4 | |
F5 BIG-IP Advanced Firewall Manager | >=11.5.1<11.6.5.1 | |
F5 BIG-IP Advanced Firewall Manager | >=12.1.0<12.1.5 | |
F5 BIG-IP Advanced Firewall Manager | >=13.0.0<13.1.3 | |
F5 BIG-IP Advanced Firewall Manager | >=14.0.0<14.0.1.1 | |
F5 BIG-IP Advanced Firewall Manager | >=14.1.0<14.1.2.4 | |
F5 BIG-IP Analytics | >=11.5.1<11.6.5.1 | |
F5 BIG-IP Analytics | >=12.1.0<12.1.5 | |
F5 BIG-IP Analytics | >=13.0.0<13.1.3 | |
F5 BIG-IP Analytics | >=14.0.0<14.0.1.1 | |
F5 BIG-IP Analytics | >=14.1.0<14.1.2.4 | |
F5 Big-ip Application Acceleration Manager | >=11.5.1<11.6.5.1 | |
F5 Big-ip Application Acceleration Manager | >=12.1.0<12.1.5 | |
F5 Big-ip Application Acceleration Manager | >=13.0.0<13.1.3 | |
F5 Big-ip Application Acceleration Manager | >=14.0.0<14.0.1.1 | |
F5 Big-ip Application Acceleration Manager | >=14.1.0<14.1.2.4 | |
F5 BIG-IP Application Security Manager | >=11.5.1<11.6.5.1 | |
F5 BIG-IP Application Security Manager | >=12.1.0<12.1.5 | |
F5 BIG-IP Application Security Manager | >=13.0.0<13.1.3 | |
F5 BIG-IP Application Security Manager | >=14.0.0<14.0.1.1 | |
F5 BIG-IP Application Security Manager | >=14.1.0<14.1.2.4 | |
F5 Big-ip Domain Name System | >=11.5.1<11.6.5.1 | |
F5 Big-ip Domain Name System | >=12.1.0<12.1.5 | |
F5 Big-ip Domain Name System | >=13.0.0<13.1.3 | |
F5 Big-ip Domain Name System | >=14.0.0<14.0.1.1 | |
F5 Big-ip Domain Name System | >=14.1.0<14.1.2.4 | |
F5 Big-ip Edge Gateway | >=11.5.1<11.6.5.1 | |
F5 Big-ip Edge Gateway | >=12.1.0<12.1.5 | |
F5 Big-ip Edge Gateway | >=13.0.0<13.1.3 | |
F5 Big-ip Edge Gateway | >=14.0.0<14.0.1.1 | |
F5 Big-ip Edge Gateway | >=14.1.0<14.1.2.4 | |
F5 Big-ip Fraud Protection Service | >=11.5.1<11.6.5.1 | |
F5 Big-ip Fraud Protection Service | >=12.1.0<12.1.5 | |
F5 Big-ip Fraud Protection Service | >=13.0.0<13.1.3 | |
F5 Big-ip Fraud Protection Service | >=14.0.0<14.0.1.1 | |
F5 Big-ip Fraud Protection Service | >=14.1.0<14.1.2.4 | |
F5 Big-ip Global Traffic Manager | >=11.5.1<11.6.5.1 | |
F5 Big-ip Global Traffic Manager | >=12.1.0<12.1.5 | |
F5 Big-ip Global Traffic Manager | >=13.0.0<13.1.3 | |
F5 Big-ip Global Traffic Manager | >=14.0.0<14.0.1.1 | |
F5 Big-ip Global Traffic Manager | >=14.1.0<14.1.2.4 | |
F5 Big-ip Link Controller | >=11.5.1<11.6.5.1 | |
F5 Big-ip Link Controller | >=12.1.0<12.1.5 | |
F5 Big-ip Link Controller | >=13.0.0<13.1.3 | |
F5 Big-ip Link Controller | >=14.0.0<14.0.1.1 | |
F5 Big-ip Link Controller | >=14.1.0<14.1.2.4 | |
F5 Big-ip Local Traffic Manager | >=11.5.1<11.6.5.1 | |
F5 Big-ip Local Traffic Manager | >=12.1.0<12.1.5 | |
F5 Big-ip Local Traffic Manager | >=13.0.0<13.1.3 | |
F5 Big-ip Local Traffic Manager | >=14.0.0<14.0.1.1 | |
F5 Big-ip Local Traffic Manager | >=14.1.0<14.1.2.4 | |
F5 Big-ip Policy Enforcement Manager | >=11.5.1<11.6.5.1 | |
F5 Big-ip Policy Enforcement Manager | >=12.1.0<12.1.5 | |
F5 Big-ip Policy Enforcement Manager | >=13.0.0<13.1.3 | |
F5 Big-ip Policy Enforcement Manager | >=14.0.0<14.0.1.1 | |
F5 Big-ip Policy Enforcement Manager | >=14.1.0<14.1.2.4 | |
F5 Big-ip Webaccelerator | >=11.5.1<11.6.5.1 | |
F5 Big-ip Webaccelerator | >=12.1.0<12.1.5 | |
F5 Big-ip Webaccelerator | >=13.0.0<13.1.3 | |
F5 Big-ip Webaccelerator | >=14.0.0<14.0.1.1 | |
F5 Big-ip Webaccelerator | >=14.1.0<14.1.2.4 | |
All of | ||
Siemens Ruggedcom Rm1224 Firmware | <6.1 | |
Siemens RUGGEDCOM RM1224 | ||
All of | ||
Siemens Ruggedcom Rox Ii Firmware | <2.13.3 | |
Siemens Ruggedcom Rox Ii | ||
All of | ||
Siemens Scalance M-800 Firmware | <6.1 | |
Siemens SCALANCE M-800 | ||
All of | ||
Siemens Scalance S615 Firmware | <6.1 | |
Siemens SCALANCE S615 | ||
All of | ||
Siemens Scalance Sc-600 Firmware | <2.0 | |
Siemens SCALANCE SC-600 | ||
All of | ||
Siemens Scalance W1700 Ieee 802.11ac Firmware | <2.0 | |
Siemens Scalance W1700 Ieee 802.11ac | ||
All of | ||
Siemens Scalance W700 Ieee 802.11a\/b\/g\/n Firmware | <6.4 | |
Siemens Scalance W700 Ieee 802.11a\/b\/g\/n | ||
All of | ||
Siemens Simatic Net Cp 1242-7 Firmware | <3.2 | |
Siemens Simatic Net Cp 1242-7 | ||
All of | ||
Siemens Simatic Net Cp 1243-1 Firmware | <3.2 | |
Siemens Simatic Net Cp 1243-1 | ||
All of | ||
Siemens Simatic Net Cp 1243-7 Lte Eu Firmware | <3.2 | |
Siemens Simatic Net Cp 1243-7 Lte Eu | ||
All of | ||
Siemens Simatic Net Cp 1243-7 Lte Us Firmware | <3.2 | |
Siemens Simatic Net Cp 1243-7 Lte Us | ||
All of | ||
Siemens Simatic Net Cp 1243-8 Irc Firmware | <3.2 | |
Siemens Simatic Net Cp 1243-8 Irc | ||
All of | ||
Siemens Simatic Net Cp 1542sp-1 Firmware | <2.1 | |
Siemens Simatic Net Cp 1542sp-1 | ||
All of | ||
Siemens Simatic Net Cp 1542sp-1 Irc Firmware | <2.1 | |
Siemens Simatic Net Cp 1542sp-1 Irc | ||
All of | ||
Siemens Simatic Net Cp 1543-1 Firmware | <2.2 | |
Siemens Simatic Net Cp 1543-1 | ||
All of | ||
Siemens Simatic Net Cp 1543sp-1 Firmware | <2.1 | |
Siemens Simatic Net Cp 1543sp-1 | ||
All of | ||
Siemens Simatic Rf185c Firmware | <1.3 | |
Siemens Simatic Rf185c | ||
All of | ||
Siemens Simatic Rf186c Firmware | <1.3 | |
Siemens Simatic Rf186c | ||
All of | ||
Siemens Simatic Rf186ci Firmware | <1.3 | |
Siemens Simatic Rf186ci | ||
All of | ||
Siemens Simatic Rf188 Firmware | <1.3 | |
Siemens Simatic Rf188 | ||
All of | ||
Siemens Simatic Rf188ci Firmware | <1.3 | |
Siemens Simatic Rf188ci | ||
All of | ||
Siemens Sinema Remote Connect Server Firmware | >=1.1<2.0.1 | |
Siemens SINEMA Remote Connect Server | ||
Siemens Ruggedcom Rm1224 Firmware | <6.1 | |
Siemens RUGGEDCOM RM1224 | ||
Siemens Ruggedcom Rox Ii Firmware | <2.13.3 | |
Siemens Ruggedcom Rox Ii | ||
Siemens Scalance M-800 Firmware | <6.1 | |
Siemens SCALANCE M-800 | ||
Siemens Scalance S615 Firmware | <6.1 | |
Siemens SCALANCE S615 | ||
Siemens Scalance Sc-600 Firmware | <2.0 | |
Siemens SCALANCE SC-600 | ||
Siemens Scalance W1700 Ieee 802.11ac Firmware | <2.0 | |
Siemens Scalance W1700 Ieee 802.11ac | ||
Siemens Scalance W700 Ieee 802.11a\/b\/g\/n Firmware | <6.4 | |
Siemens Scalance W700 Ieee 802.11a\/b\/g\/n | ||
Siemens Simatic Net Cp 1242-7 Firmware | <3.2 | |
Siemens Simatic Net Cp 1242-7 | ||
Siemens Simatic Net Cp 1243-1 Firmware | <3.2 | |
Siemens Simatic Net Cp 1243-1 | ||
Siemens Simatic Net Cp 1243-7 Lte Eu Firmware | <3.2 | |
Siemens Simatic Net Cp 1243-7 Lte Eu | ||
Siemens Simatic Net Cp 1243-7 Lte Us Firmware | <3.2 | |
Siemens Simatic Net Cp 1243-7 Lte Us | ||
Siemens Simatic Net Cp 1243-8 Irc Firmware | <3.2 | |
Siemens Simatic Net Cp 1243-8 Irc | ||
Siemens Simatic Net Cp 1542sp-1 Firmware | <2.1 | |
Siemens Simatic Net Cp 1542sp-1 | ||
Siemens Simatic Net Cp 1542sp-1 Irc Firmware | <2.1 | |
Siemens Simatic Net Cp 1542sp-1 Irc | ||
Siemens Simatic Net Cp 1543-1 Firmware | <2.2 | |
Siemens Simatic Net Cp 1543-1 | ||
Siemens Simatic Net Cp 1543sp-1 Firmware | <2.1 | |
Siemens Simatic Net Cp 1543sp-1 | ||
Siemens Simatic Rf185c Firmware | <1.3 | |
Siemens Simatic Rf185c | ||
Siemens Simatic Rf186c Firmware | <1.3 | |
Siemens Simatic Rf186c | ||
Siemens Simatic Rf186ci Firmware | <1.3 | |
Siemens Simatic Rf186ci | ||
Siemens Simatic Rf188 Firmware | <1.3 | |
Siemens Simatic Rf188 | ||
Siemens Simatic Rf188ci Firmware | <1.3 | |
Siemens Simatic Rf188ci | ||
Siemens Sinema Remote Connect Server Firmware | >=1.1<2.0.1 | |
Siemens SINEMA Remote Connect Server | ||
debian/linux | 5.10.223-1 5.10.226-1 6.1.123-1 6.1.119-1 6.12.9-1 6.12.10-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this Linux kernel vulnerability is CVE-2018-5391.
CVE-2018-5391 has a severity level of high.
The affected software for CVE-2018-5391 includes various versions of the Linux kernel, such as linux-aws, linux-azure, linux-euclid, linux-oem, linux, and more.
To fix CVE-2018-5391, update to the recommended versions of the affected software provided by the respective vendors.
You can find more information about CVE-2018-5391 on the Red Hat and CERT websites, as well as the official Linux kernel git repository.