CVE-2018-5390
published 2018-08-06CVE-2018-5390: Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can…
PriorityP355high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
73.72%
99.4th percentile
Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can lead to a denial of service.
Affected
122 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| a10networks | advanced_core_operating_system | — | — |
| a10networks | advanced_core_operating_system | — | — |
| a10networks | advanced_core_operating_system | — | — |
| a10networks | advanced_core_operating_system | — | — |
| a10networks | advanced_core_operating_system | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| cisco | collaboration_meeting_rooms | — | — |
| cisco | digital_network_architecture_center | — | — |
| cisco | expressway | — | — |
| cisco | expressway | — | — |
| cisco | expressway | — | — |
| cisco | expressway | — | — |
| cisco | expressway | — | — |
| cisco | expressway | — | — |
| cisco | meeting_management | — | — |
| cisco | meeting_management | — | — |
| cisco | network_assurance_engine | — | — |
| cisco | telepresence_conductor_firmware | — | — |
| cisco | telepresence_conductor_firmware | — | — |
| cisco | telepresence_conductor_firmware | — | — |
| cisco | telepresence_conductor_firmware | — | — |
| cisco | telepresence_conductor_firmware | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Target functions: force expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet to trigger DoS ↗
- →Attack vector: send a stream of specially crafted TCP packets within an established TCP session at low transfer rates to trigger algorithmic complexity DoS — spoofed IPs cannot be used as an established session is required ↗
- →Attack can be executed using low transfer rates of TCP packets, unlike typical DDoS — monitor for sustained low-rate TCP sessions causing high CPU in kernel TCP reassembly paths ↗
- →Affected scope: Linux Kernel versions 4.9 and later are vulnerable (publicly known as SegmentSmack) ↗
- ·A sustained DoS requires the attacker to maintain a continuous stream of malicious traffic over an established TCP session; single-packet or spoofed-source attacks are not sufficient to trigger the vulnerability ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu5.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens RUGGEDCOM, SCALANCE, SIMATIC, SINEMA (Update B)
cisa_ics·2020-05-12·CVSS 7.5
[HIGH] Siemens RUGGEDCOM, SCALANCE, SIMATIC, SINEMA (Update B)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens RUGGEDCOM, SCALANCE, SIMATIC, SINEMA (Update B)
Last RevisedSeptember 08, 2020
Alert CodeICSA-20-105-05
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.5
- ATTENTION: Exploitable remotely/low skill level to exploit
- Vendor: Siemens
- Equipment: RUGGEDCOM, SCALANCE, SIMATIC, SINEMA
- Vulnerabilities: Uncontrolled Resource Consumption, Improper Input Validation
## 2. UPDATE INFORMATION
This updated advisory is a follow-up to the advisory update titled ICSA-20-105-05 Siemens IE/PB-Link, RUGGEDCOM, SCALANCE, SIMATIC, SINEMA (Update A) that was published May 12, 2020, on the ICS w
Palo Alto
Information about SegmentSmack findings
vendor_paloalto·2018-09-19·CVSS 7.5
CVE-2018-5390 [HIGH] CWE-20 Information about SegmentSmack findings
Information about SegmentSmack findings
Palo Alto Networks is aware of recent vulnerability disclousre, known as SegmentSmack, that affects Linux kernel 4.9 and later. At this time, our findings show that Palo Alto Networks PAN-OS devices are not vulnerable to this disclosure (CVE-2018-5390).
PAN-OS/Panorama platforms are not impacted by this vulnerability.
Affected products: PAN-OS
Solution: N/A
Workaround: Our NGFW users can use the configuration option bypass-exceed-oo-queue with value no which will provide protection from CVE-2018-5390 for devices positioned behind the firewall. For more information on configuration, please refer to the Best Practices for Securing Your Network from Layer 4 and Layer 7 Evasions document: https://www.paloaltonetworks.com/documentation/61/pan-os/pan-o
Ubuntu
Linux kernel vulnerability
vendor_ubuntu·2018-09-11
CVE-2018-5390 Linux kernel vulnerability
Title: Linux kernel vulnerability
Summary: The system could be made to crash if it received specially crafted
network traffic.
Juha-Matti Tilli discovered that the TCP implementation in the Linux kernel
performed algorithmically expensive operations in some situations when
handling incoming packets. A remote attacker could use this to cause a
denial of service.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, li
Cisco
Linux and FreeBSD Kernels TCP Reassembly Denial of Service Vulnerabilities Affecting Cisco Products: August 2018
vendor_cisco·2018-08-24
CVE-2018-5390 [HIGH] CWE-400 Linux and FreeBSD Kernels TCP Reassembly Denial of Service Vulnerabilities Affecting Cisco Products: August 2018
Linux and FreeBSD Kernels TCP Reassembly Denial of Service Vulnerabilities Affecting Cisco Products: August 2018
On August 6, 2018, the Vulnerability Coordination team of the National Cyber Security Centre of Finland (NCSC-FI) and the CERT Coordination Center (CERT/CC) disclosed vulnerabilities in the TCP stacks that are used by the Linux and FreeBSD kernels. These vulnerabilities are publicly known as SegmentSmack.
The vulnerabilities could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. An attack could be executed by using low transfer rates of TCP packets, unlike typical distributed denial of service (DDoS) attacks.
The vulnerabilities are due to inefficient TCP reassembly algorithms in the TCP stacks that are used by the af
Ubuntu
Linux kernel (Trusty HWE) regressions
vendor_ubuntu·2018-08-21·CVSS 5.5
CVE-2018-3620 [MEDIUM] Linux kernel (Trusty HWE) regressions
Title: Linux kernel (Trusty HWE) regressions
Summary: USN-3742-2 introduced regressions in the Linux Hardware Enablement
(HWE) kernel for Ubuntu 12.04 ESM.
USN-3742-2 introduced mitigations in the Linux Hardware Enablement
(HWE) kernel for Ubuntu 12.04 ESM to address L1 Terminal Fault (L1TF)
vulnerabilities (CVE-2018-3620, CVE-2018-3646). Unfortunately, the
update introduced regressions that caused kernel panics when booting
in some environments as well as preventing Java applications from
starting. This update fixes the problems.
We apologize for the inconvenience.
Original advisory details:
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a malicious process that is executing on the CPU
core. This vulnerability is also known as L1 Ter
Ubuntu
Linux kernel regressions
vendor_ubuntu·2018-08-17·CVSS 5.6
CVE-2018-3620 [MEDIUM] Linux kernel regressions
Title: Linux kernel regressions
Summary: Several security issues were fixed in the Linux kernel.
USN-3741-1 introduced mitigations in the Linux kernel for Ubuntu 14.04
LTS to address L1 Terminal Fault (L1TF) vulnerabilities (CVE-2018-3620,
CVE-2018-3646). Unfortunately, the update introduced regressions
that caused kernel panics when booting in some environments as well
as preventing Java applications from starting. This update fixes
the problems.
We apologize for the inconvenience.
Original advisory details:
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a malicious process that is executing on the CPU
core. This vulnerability is also known as L1 Terminal Fault (L1TF). A local
attacker in a guest virtual machine could use this to exp
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2018-08-14·CVSS 5.6
CVE-2018-3620 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a malicious process that is executing on the CPU
core. This vulnerability is also known as L1 Terminal Fault (L1TF). A local
attacker in a guest virtual machine could use this to expose sensitive
information (memory from other guests or the host OS). (CVE-2018-3646)
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a malicious process that is executing on the CPU
core. This vulnerability is also known as L1 Terminal Fault (L1TF). A local
attacker could use this to expose sensitive information (memory from the
kernel or other processes). (CVE-20
Ubuntu
Linux kernel (Xenial HWE) vulnerabilities
vendor_ubuntu·2018-08-14·CVSS 5.6
CVE-2018-3620 [MEDIUM] Linux kernel (Xenial HWE) vulnerabilities
Title: Linux kernel (Xenial HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3741-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 LTS.
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a malicious process that is executing on the CPU
core. This vulnerability is also known as L1 Terminal Fault (L1TF). A local
attacker in a guest virtual machine could use this to expose sensitive
information (memory from other guests or the host OS). (CVE-2018-3646)
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a mali
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2018-08-14·CVSS 5.5
CVE-2017-18344 [MEDIUM] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3742-1 fixed vulnerabilities in the Linux kernel for Ubuntu 14.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 14.04 for Ubuntu
12.04 ESM.
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a malicious process that is executing on the CPU
core. This vulnerability is also known as L1 Terminal Fault (L1TF). A local
attacker in a guest virtual machine could use this to expose sensitive
information (memory from other guests or the host OS). (CVE-2018-3646)
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a maliciou
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2018-08-14·CVSS 5.5
CVE-2017-18344 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a malicious process that is executing on the CPU
core. This vulnerability is also known as L1 Terminal Fault (L1TF). A local
attacker in a guest virtual machine could use this to expose sensitive
information (memory from other guests or the host OS). (CVE-2018-3646)
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a malicious process that is executing on the CPU
core. This vulnerability is also known as L1 Terminal Fault (L1TF). A local
attacker could use this to expose sensitive information (memory from the
kernel or other processes). (CVE-20
Red Hat
kernel: TCP segments with random offsets allow a remote denial of service (SegmentSmack)
vendor_redhat·2018-08-06·CVSS 7.5
CVE-2018-5390 [HIGH] CWE-400 kernel: TCP segments with random offsets allow a remote denial of service (SegmentSmack)
kernel: TCP segments with random offsets allow a remote denial of service (SegmentSmack)
Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can lead to a denial of service.
A flaw named SegmentSmack was found in the way the Linux kernel handled specially crafted TCP packets. A remote attacker could use this flaw to trigger time and calculation expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() functions by sending specially modified packets within ongoing TCP sessions which could lead to a CPU saturation and hence a denial of service on the system. Maintaining the denial of service condition requires continuous two-way TCP sessions to a reachable open port, thus the
Ubuntu
Linux kernel vulnerability
vendor_ubuntu·2018-08-06
CVE-2018-5390 Linux kernel vulnerability
Title: Linux kernel vulnerability
Summary: The system could be made unavailable if it received specially crafted
network traffic.
Juha-Matti Tilli discovered that the TCP implementation in the Linux kernel
performed algorithmically expensive operations in some situations when
handling incoming packets. A remote attacker could use this to cause a
denial of service.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE,
Ubuntu
Linux kernel (HWE) vulnerability
vendor_ubuntu·2018-08-06
CVE-2018-5390 Linux kernel (HWE) vulnerability
Title: Linux kernel (HWE) vulnerability
Summary: The system could be made unavailable if it received specially crafted
network traffic.
USN-3732-1 fixed vulnerabilities in the Linux kernel for Ubuntu 18.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 18.04 LTS for Ubuntu
16.04 LTS.
Juha-Matti Tilli discovered that the TCP implementation in the Linux kernel
performed algorithmically expensive operations in some situations when
handling incoming packets. A remote attacker could use this to cause a
denial of service.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version num
Debian
CVE-2018-5390: linux - Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_col...
vendor_debian·2018·CVSS 7.5
CVE-2018-5390 [HIGH] CVE-2018-5390: linux - Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_col...
Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can lead to a denial of service.
Scope: local
bookworm: resolved (fixed in 4.17.14-1)
bullseye: resolved (fixed in 4.17.14-1)
forky: resolved (fixed in 4.17.14-1)
sid: resolved (fixed in 4.17.14-1)
trixie: resolved (fixed in 4.17.14-1)
Cisco
Linux and FreeBSD Kernels TCP Reassembly Denial of Service Vulnerabilities Affecting Cisco Products: August 2018
vendor_cisco
CVE-2018-5390 Linux and FreeBSD Kernels TCP Reassembly Denial of Service Vulnerabilities Affecting Cisco Products: August 2018
CVE-2018-5390: Linux and FreeBSD Kernels TCP Reassembly Denial of Service Vulnerabilities Affecting Cisco Products: August 2018
On August 6, 2018, the Vulnerability Coordination team of the National Cyber Security Centre of Finland (NCSC-FI) and the CERT Coordination Center (CERT/CC) disclosed vulnerabilities in the TCP stacks that are used by the Linux and FreeBSD kernels. These vulnerabilities are publicly known as SegmentSmack . The vulnerabilities could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. An attack could be executed by using low transfer rates of TCP packets, unlike typical distributed denial of service (DDoS) attacks. The vulnerabilities are due to inefficient TCP reassembly algorithms in the TCP stacks that are
GHSA
GHSA-grv8-gqh3-fmc9: Linux kernel versions 4
ghsa_unreviewed·2022-05-13
CVE-2018-5390 [HIGH] CWE-400 GHSA-grv8-gqh3-fmc9: Linux kernel versions 4
Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can lead to a denial of service.
OSV
linux regressions
osv·2018-08-17·CVSS 5.6
CVE-2018-3620 [MEDIUM] linux regressions
linux regressions
USN-3741-1 introduced mitigations in the Linux kernel for Ubuntu 14.04
LTS to address L1 Terminal Fault (L1TF) vulnerabilities (CVE-2018-3620,
CVE-2018-3646). Unfortunately, the update introduced regressions
that caused kernel panics when booting in some environments as well
as preventing Java applications from starting. This update fixes
the problems.
We apologize for the inconvenience.
Original advisory details:
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a malicious process that is executing on the CPU
core. This vulnerability is also known as L1 Terminal Fault (L1TF). A local
attacker in a guest virtual machine could use this to expose sensitive
information (memory from other guests or the host OS). (CVE-2018-3
OSV
linux vulnerabilities
osv·2018-08-14·CVSS 5.5
CVE-2018-3646 [MEDIUM] linux vulnerabilities
linux vulnerabilities
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a malicious process that is executing on the CPU
core. This vulnerability is also known as L1 Terminal Fault (L1TF). A local
attacker in a guest virtual machine could use this to expose sensitive
information (memory from other guests or the host OS). (CVE-2018-3646)
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a malicious process that is executing on the CPU
core. This vulnerability is also known as L1 Terminal Fault (L1TF). A local
attacker could use this to expose sensitive information (memory from the
kernel or other processes). (CVE-2018-3620)
Andrey Konovalov discovered an out-of-bounds read in the POSIX
timers
OSV
linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
osv·2018-08-14·CVSS 5.6
CVE-2018-3646 [MEDIUM] linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a malicious process that is executing on the CPU
core. This vulnerability is also known as L1 Terminal Fault (L1TF). A local
attacker in a guest virtual machine could use this to expose sensitive
information (memory from other guests or the host OS). (CVE-2018-3646)
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a malicious process that is executing on the CPU
core. This vulnerability is also known as L1 Terminal Fault (L1TF). A local
attacker could use this to expose sensitive information (memory from the
kernel or other processes). (CVE-2018-3620)
Juha-Matti Tilli
OSV
linux-lts-xenial, linux-aws vulnerabilities
osv·2018-08-14·CVSS 5.6
[MEDIUM] linux-lts-xenial, linux-aws vulnerabilities
linux-lts-xenial, linux-aws vulnerabilities
USN-3741-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 LTS.
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a malicious process that is executing on the CPU
core. This vulnerability is also known as L1 Terminal Fault (L1TF). A local
attacker in a guest virtual machine could use this to expose sensitive
information (memory from other guests or the host OS). (CVE-2018-3646)
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a malicious process that is executing on the CPU
core. This vulnerability is
OSV
CVE-2018-5390: Linux kernel versions 4
osv·2018-08-06·CVSS 7.5
CVE-2018-5390 [HIGH] CVE-2018-5390: Linux kernel versions 4
Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can lead to a denial of service.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-5390 kernel: TCP segments with random offsets allow a remote denial of service (SegmentSmack) [fedora-all]
bugzilla·2018-08-06·CVSS 7.5
CVE-2018-5390 [HIGH] CVE-2018-5390 kernel: TCP segments with random offsets allow a remote denial of service (SegmentSmack) [fedora-all]
CVE-2018-5390 kernel: TCP segments with random offsets allow a remote denial of service (SegmentSmack) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this iss
Bugzilla
CVE-2018-5390 kernel: TCP segments with random offsets allow a remote denial of service (SegmentSmack)
bugzilla·2018-07-17·CVSS 7.5
CVE-2018-5390 [HIGH] CVE-2018-5390 kernel: TCP segments with random offsets allow a remote denial of service (SegmentSmack)
CVE-2018-5390 kernel: TCP segments with random offsets allow a remote denial of service (SegmentSmack)
A flaw named SegmentSmack was found in the way the Linux kernel handled specially crafted TCP packets. A remote attacker could use this flaw to trigger time and calculation expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() functions by sending specially modified packets within ongoing TCP sessions which could lead to a CPU saturation and hence a denial of service on the system. Maintaining the denial of service condition requires continuous two-way TCP sessions to a reachable open port, thus the attacks cannot be performed using spoofed IP addresses.
External References:
https://access.redhat.com/articles/3553061
https://www.kb.cert.org/vuls/id/962459
https://www.
http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2018-004.txthttp://www.huawei.com/en/psirt/security-advisories/huawei-sa-20181031-02-linux-enhttp://www.openwall.com/lists/oss-security/2019/06/28/2http://www.openwall.com/lists/oss-security/2019/07/06/3http://www.openwall.com/lists/oss-security/2019/07/06/4http://www.securityfocus.com/bid/104976http://www.securitytracker.com/id/1041424http://www.securitytracker.com/id/1041434https://access.redhat.com/errata/RHSA-2018:2384https://access.redhat.com/errata/RHSA-2018:2395https://access.redhat.com/errata/RHSA-2018:2402https://access.redhat.com/errata/RHSA-2018:2403https://access.redhat.com/errata/RHSA-2018:2645https://access.redhat.com/errata/RHSA-2018:2776https://access.redhat.com/errata/RHSA-2018:2785https://access.redhat.com/errata/RHSA-2018:2789https://access.redhat.com/errata/RHSA-2018:2790https://access.redhat.com/errata/RHSA-2018:2791https://access.redhat.com/errata/RHSA-2018:2924https://access.redhat.com/errata/RHSA-2018:2933https://access.redhat.com/errata/RHSA-2018:2948https://cert-portal.siemens.com/productcert/pdf/ssa-377115.pdfhttps://git.kernel.org/pub/scm/linux/kernel/git/davem/net.git/commit/?id=1a4f14bab1868b443f0dd3c55b689a478f82e72ehttps://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0https://lists.debian.org/debian-lts-announce/2018/08/msg00014.htmlhttps://security.netapp.com/advisory/ntap-20180815-0003/https://support.f5.com/csp/article/K95343321https://support.f5.com/csp/article/K95343321?utm_source=f5support&%3Butm_medium=RSShttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180824-linux-tcphttps://usn.ubuntu.com/3732-1/https://usn.ubuntu.com/3732-2/https://usn.ubuntu.com/3741-1/https://usn.ubuntu.com/3741-2/https://usn.ubuntu.com/3742-1/https://usn.ubuntu.com/3742-2/https://usn.ubuntu.com/3763-1/https://www.a10networks.com/support/security-advisories/tcp-ip-cve-2018-5390-segmentsmackhttps://www.debian.org/security/2018/dsa-4266https://www.kb.cert.org/vuls/id/962459https://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.htmlhttps://www.synology.com/support/security/Synology_SA_18_41http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2018-004.txthttp://www.huawei.com/en/psirt/security-advisories/huawei-sa-20181031-02-linux-enhttp://www.openwall.com/lists/oss-security/2019/06/28/2http://www.openwall.com/lists/oss-security/2019/07/06/3http://www.openwall.com/lists/oss-security/2019/07/06/4http://www.securityfocus.com/bid/104976http://www.securitytracker.com/id/1041424http://www.securitytracker.com/id/1041434https://access.redhat.com/errata/RHSA-2018:2384https://access.redhat.com/errata/RHSA-2018:2395https://access.redhat.com/errata/RHSA-2018:2402https://access.redhat.com/errata/RHSA-2018:2403https://access.redhat.com/errata/RHSA-2018:2645https://access.redhat.com/errata/RHSA-2018:2776https://access.redhat.com/errata/RHSA-2018:2785https://access.redhat.com/errata/RHSA-2018:2789https://access.redhat.com/errata/RHSA-2018:2790https://access.redhat.com/errata/RHSA-2018:2791https://access.redhat.com/errata/RHSA-2018:2924https://access.redhat.com/errata/RHSA-2018:2933https://access.redhat.com/errata/RHSA-2018:2948https://cert-portal.siemens.com/productcert/pdf/ssa-377115.pdfhttps://git.kernel.org/pub/scm/linux/kernel/git/davem/net.git/commit/?id=1a4f14bab1868b443f0dd3c55b689a478f82e72ehttps://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0https://lists.debian.org/debian-lts-announce/2018/08/msg00014.htmlhttps://security.netapp.com/advisory/ntap-20180815-0003/https://support.f5.com/csp/article/K95343321https://support.f5.com/csp/article/K95343321?utm_source=f5support&%3Butm_medium=RSShttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180824-linux-tcphttps://usn.ubuntu.com/3732-1/https://usn.ubuntu.com/3732-2/https://usn.ubuntu.com/3741-1/https://usn.ubuntu.com/3741-2/https://usn.ubuntu.com/3742-1/https://usn.ubuntu.com/3742-2/https://usn.ubuntu.com/3763-1/https://www.a10networks.com/support/security-advisories/tcp-ip-cve-2018-5390-segmentsmackhttps://www.debian.org/security/2018/dsa-4266https://www.kb.cert.org/vuls/id/962459https://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.htmlhttps://www.synology.com/support/security/Synology_SA_18_41
2018-08-06
Published