cbcvebase.
CVE-2018-5390
published 2018-08-06

CVE-2018-5390: Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can…

PriorityP355high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
73.54%
99.4th percentile
Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can lead to a denial of service.

Affected

122 ranges· showing 25
VendorProductVersion rangeFixed in
a10networksadvanced_core_operating_system
a10networksadvanced_core_operating_system
a10networksadvanced_core_operating_system
a10networksadvanced_core_operating_system
a10networksadvanced_core_operating_system
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
ciscocollaboration_meeting_rooms
ciscodigital_network_architecture_center
ciscoexpressway
ciscoexpressway
ciscoexpressway
ciscoexpressway
ciscoexpressway
ciscoexpressway
ciscomeeting_management
ciscomeeting_management
cisconetwork_assurance_engine
ciscotelepresence_conductor_firmware
ciscotelepresence_conductor_firmware
ciscotelepresence_conductor_firmware
ciscotelepresence_conductor_firmware
ciscotelepresence_conductor_firmware

Detection & IOCsextracted from sources · hover to see the quote

  • Target functions: force expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet to trigger DoS
  • Attack vector: send a stream of specially crafted TCP packets within an established TCP session at low transfer rates to trigger algorithmic complexity DoS — spoofed IPs cannot be used as an established session is required
  • Attack can be executed using low transfer rates of TCP packets, unlike typical DDoS — monitor for sustained low-rate TCP sessions causing high CPU in kernel TCP reassembly paths
  • Affected scope: Linux Kernel versions 4.9 and later are vulnerable (publicly known as SegmentSmack)
  • ·A sustained DoS requires the attacker to maintain a continuous stream of malicious traffic over an established TCP session; single-packet or spoofed-source attacks are not sufficient to trigger the vulnerability

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu5.6MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.