CVE-2018-5391
published 2018-09-06CVE-2018-5391: The Linux kernel, versions 3.9+, is vulnerable to a denial of service attack with low rates of specially modified packets targeting IP fragment re-assembly. An…
PriorityP183high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
ITWVulnCheck KEVRansomware
Exploited in the wild
EPSS
24.57%
97.6th percentile
The Linux kernel, versions 3.9+, is vulnerable to a denial of service attack with low rates of specially modified packets targeting IP fragment re-assembly. An attacker may cause a denial of service condition by sending specially crafted IP fragments. Various vulnerabilities in IP fragmentation have been discovered and fixed over the years. The current vulnerability (CVE-2018-5391) became exploitable in the Linux kernel with the increase of the IP fragment reassembly queue size.
Affected
133 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | linux | < linux 4.17.15-1 (bookworm) | linux 4.17.15-1 (bookworm) |
| f5 | big-ip_access_policy_manager | >= 11.5.1 < 11.6.5.1 | 11.6.5.1 |
| f5 | big-ip_access_policy_manager | >= 12.1.0 < 12.1.5 | 12.1.5 |
| f5 | big-ip_access_policy_manager | >= 13.0.0 < 13.1.3 | 13.1.3 |
| f5 | big-ip_access_policy_manager | >= 14.0.0 < 14.0.1.1 | 14.0.1.1 |
| f5 | big-ip_access_policy_manager | >= 14.1.0 < 14.1.2.4 | 14.1.2.4 |
| f5 | big-ip_advanced_firewall_manager | >= 11.5.1 < 11.6.5.1 | 11.6.5.1 |
| f5 | big-ip_advanced_firewall_manager | >= 12.1.0 < 12.1.5 | 12.1.5 |
| f5 | big-ip_advanced_firewall_manager | >= 13.0.0 < 13.1.3 | 13.1.3 |
| f5 | big-ip_advanced_firewall_manager | >= 14.0.0 < 14.0.1.1 | 14.0.1.1 |
| f5 | big-ip_advanced_firewall_manager | >= 14.1.0 < 14.1.2.4 | 14.1.2.4 |
| f5 | big-ip_analytics | >= 11.5.1 < 11.6.5.1 | 11.6.5.1 |
| f5 | big-ip_analytics | >= 12.1.0 < 12.1.5 | 12.1.5 |
| f5 | big-ip_analytics | >= 13.0.0 < 13.1.3 | 13.1.3 |
| f5 | big-ip_analytics | >= 14.0.0 < 14.0.1.1 | 14.0.1.1 |
| f5 | big-ip_analytics | >= 14.1.0 < 14.1.2.4 | 14.1.2.4 |
| f5 | big-ip_application_acceleration_manager | >= 11.5.1 < 11.6.5.1 | 11.6.5.1 |
| f5 | big-ip_application_acceleration_manager | >= 12.1.0 < 12.1.5 | 12.1.5 |
| f5 | big-ip_application_acceleration_manager | >= 13.0.0 < 13.1.3 | 13.1.3 |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect FragmentSmack DoS: look for high rates of incoming IP fragment packets (IPv4 and IPv6) targeting a host, especially with randomly or specially crafted fragment offsets designed to trigger expensive reassembly algorithms and cause CPU saturation. ↗
- →Monitor kernel sysctl values net.ipv4.ipfrag_high_thresh and net.ipv4.ipfrag_low_thresh (and IPv6 counterparts net.ipv6.ipfrag_high_thresh / net.ipv6.ipfrag_low_thresh); default values of 4MB/3MB indicate an unmitigated system. Mitigated systems should show 262144 (256 kB) / 196608 (192 kB) or lower. ↗
- →Affected Linux kernel versions start at 3.9; systems running Linux kernel 3.9 or later that have not applied the fix (Debian: kernel 4.17.15-1) should be flagged as vulnerable. ↗
- →For PAN-OS environments, the attack surface is limited to the Management Plane interface; monitor for unexpected fragmented traffic directed at the management interface of PAN-OS devices. ↗
- ·The vulnerability became exploitable due to an increase in the IP fragment reassembly queue size; the root cause is a configuration/kernel change, not just a code bug. ↗
- ·Lowering ipfrag_high_thresh to 256 kB limits the reassembly queue to only two 64K fragments simultaneously, which may break applications relying on large UDP packets. ↗
- ·RHEL 5 is affected but will not receive a fix due to end-of-life; RHEL 8 is not affected. Detection/patching scope should be adjusted accordingly. ↗
- ·PAN-OS affected versions span 6.1.21 and earlier, 7.1.19 and earlier, 8.0.12 and earlier, and 8.1.4 and earlier across multiple hardware platforms; fixed in PAN-OS 6.1.22, 7.1.20, 8.0.13, and 8.1.5 respectively. ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
osv7.5HIGH
vulncheck7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu5.6MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens RUGGEDCOM, SCALANCE, SIMATIC, SINEMA (Update B)
cisa_ics·2020-05-12·CVSS 7.5
[HIGH] Siemens RUGGEDCOM, SCALANCE, SIMATIC, SINEMA (Update B)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens RUGGEDCOM, SCALANCE, SIMATIC, SINEMA (Update B)
Last RevisedSeptember 08, 2020
Alert CodeICSA-20-105-05
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.5
- ATTENTION: Exploitable remotely/low skill level to exploit
- Vendor: Siemens
- Equipment: RUGGEDCOM, SCALANCE, SIMATIC, SINEMA
- Vulnerabilities: Uncontrolled Resource Consumption, Improper Input Validation
## 2. UPDATE INFORMATION
This updated advisory is a follow-up to the advisory update titled ICSA-20-105-05 Siemens IE/PB-Link, RUGGEDCOM, SCALANCE, SIMATIC, SINEMA (Update A) that was published May 12, 2020, on the ICS w
Palo Alto
Information about FragmentSmack findings
vendor_paloalto·2018-09-19·CVSS 7.5
CVE-2018-5391 [HIGH] CWE-20 Information about FragmentSmack findings
Information about FragmentSmack findings
Palo Alto Networks is aware of recent vulnerability disclosure, known as FragmentSmack, that affects Linux kernel 3.9 and later. At this time, our findings show that some Palo Alto Networks devices running specific versions of PAN-OS are vulnerable to this disclosure. (CVE-2018-5391). This security advisory will be updated as more information becomes available or if there are changes in the impact of these vulnerabilities.
A flaw named FragmentSmack was found in the way the Linux kernel handled reassembly of fragmented IPv4 and IPv6 packets. To exploit this vulnerability a remote attacker could send specially crafted packets that trigger time and calculation expensive fragment reassembly algorithms and cause CPU saturation (a denial of service on t
Cisco
Linux Kernel IP Fragment Reassembly Denial of Service Vulnerability Affecting Cisco Products: August 2018
vendor_cisco·2018-08-24
CVE-2018-5391 [HIGH] CWE-400 Linux Kernel IP Fragment Reassembly Denial of Service Vulnerability Affecting Cisco Products: August 2018
Linux Kernel IP Fragment Reassembly Denial of Service Vulnerability Affecting Cisco Products: August 2018
On August 14, 2018, the Vulnerability Coordination team of the National Cyber Security Centre of Finland (NCSC-FI) and the CERT Coordination Center (CERT/CC) disclosed a vulnerability in the IP stack that is used by the Linux Kernel. This vulnerability is publicly known as FragmentSmack.
The vulnerability could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. An attack could be executed by an attacker who can submit a stream of fragmented IPv4 or IPv6 packets that are designed to trigger the issue on an affected device.
The vulnerability is due to inefficient IPv4 and IPv6 fragment reassembly algorithms in the IP stack that
Ubuntu
Linux kernel (Trusty HWE) regressions
vendor_ubuntu·2018-08-21·CVSS 5.5
CVE-2018-3620 [MEDIUM] Linux kernel (Trusty HWE) regressions
Title: Linux kernel (Trusty HWE) regressions
Summary: USN-3742-2 introduced regressions in the Linux Hardware Enablement
(HWE) kernel for Ubuntu 12.04 ESM.
USN-3742-2 introduced mitigations in the Linux Hardware Enablement
(HWE) kernel for Ubuntu 12.04 ESM to address L1 Terminal Fault (L1TF)
vulnerabilities (CVE-2018-3620, CVE-2018-3646). Unfortunately, the
update introduced regressions that caused kernel panics when booting
in some environments as well as preventing Java applications from
starting. This update fixes the problems.
We apologize for the inconvenience.
Original advisory details:
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a malicious process that is executing on the CPU
core. This vulnerability is also known as L1 Ter
Ubuntu
Linux kernel regressions
vendor_ubuntu·2018-08-17·CVSS 5.6
CVE-2018-3620 [MEDIUM] Linux kernel regressions
Title: Linux kernel regressions
Summary: Several security issues were fixed in the Linux kernel.
USN-3741-1 introduced mitigations in the Linux kernel for Ubuntu 14.04
LTS to address L1 Terminal Fault (L1TF) vulnerabilities (CVE-2018-3620,
CVE-2018-3646). Unfortunately, the update introduced regressions
that caused kernel panics when booting in some environments as well
as preventing Java applications from starting. This update fixes
the problems.
We apologize for the inconvenience.
Original advisory details:
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a malicious process that is executing on the CPU
core. This vulnerability is also known as L1 Terminal Fault (L1TF). A local
attacker in a guest virtual machine could use this to exp
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2018-08-14·CVSS 5.6
CVE-2018-3620 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a malicious process that is executing on the CPU
core. This vulnerability is also known as L1 Terminal Fault (L1TF). A local
attacker in a guest virtual machine could use this to expose sensitive
information (memory from other guests or the host OS). (CVE-2018-3646)
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a malicious process that is executing on the CPU
core. This vulnerability is also known as L1 Terminal Fault (L1TF). A local
attacker could use this to expose sensitive information (memory from the
kernel or other processes). (CVE-20
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2018-08-14·CVSS 5.6
CVE-2018-3620 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a malicious process that is executing on the CPU
core. This vulnerability is also known as L1 Terminal Fault (L1TF). A local
attacker in a guest virtual machine could use this to expose sensitive
information (memory from other guests or the host OS). (CVE-2018-3646)
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a malicious process that is executing on the CPU
core. This vulnerability is also known as L1 Terminal Fault (L1TF). A local
attacker could use this to expose sensitive information (memory from the
kernel or other processes). (CVE-20
Ubuntu
Linux kernel (Xenial HWE) vulnerabilities
vendor_ubuntu·2018-08-14·CVSS 5.6
CVE-2018-3620 [MEDIUM] Linux kernel (Xenial HWE) vulnerabilities
Title: Linux kernel (Xenial HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3741-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 LTS.
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a malicious process that is executing on the CPU
core. This vulnerability is also known as L1 Terminal Fault (L1TF). A local
attacker in a guest virtual machine could use this to expose sensitive
information (memory from other guests or the host OS). (CVE-2018-3646)
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a mali
Red Hat
kernel: IP fragments with random offsets allow a remote denial of service (FragmentSmack)
vendor_redhat·2018-08-14·CVSS 7.5
CVE-2018-5391 [HIGH] CWE-400 kernel: IP fragments with random offsets allow a remote denial of service (FragmentSmack)
kernel: IP fragments with random offsets allow a remote denial of service (FragmentSmack)
The Linux kernel, versions 3.9+, is vulnerable to a denial of service attack with low rates of specially modified packets targeting IP fragment re-assembly. An attacker may cause a denial of service condition by sending specially crafted IP fragments. Various vulnerabilities in IP fragmentation have been discovered and fixed over the years. The current vulnerability (CVE-2018-5391) became exploitable in the Linux kernel with the increase of the IP fragment reassembly queue size.
A flaw named FragmentSmack was found in the way the Linux kernel handled reassembly of fragmented IPv4 and IPv6 packets. A remote attacker could use this flaw to trigger time and calculation expensive fragment reassembly alg
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2018-08-14·CVSS 5.5
CVE-2017-18344 [MEDIUM] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3742-1 fixed vulnerabilities in the Linux kernel for Ubuntu 14.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 14.04 for Ubuntu
12.04 ESM.
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a malicious process that is executing on the CPU
core. This vulnerability is also known as L1 Terminal Fault (L1TF). A local
attacker in a guest virtual machine could use this to expose sensitive
information (memory from other guests or the host OS). (CVE-2018-3646)
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a maliciou
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2018-08-14·CVSS 5.5
CVE-2017-18344 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a malicious process that is executing on the CPU
core. This vulnerability is also known as L1 Terminal Fault (L1TF). A local
attacker in a guest virtual machine could use this to expose sensitive
information (memory from other guests or the host OS). (CVE-2018-3646)
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a malicious process that is executing on the CPU
core. This vulnerability is also known as L1 Terminal Fault (L1TF). A local
attacker could use this to expose sensitive information (memory from the
kernel or other processes). (CVE-20
Ubuntu
Linux kernel (HWE) vulnerabilities
vendor_ubuntu·2018-08-14·CVSS 5.6
CVE-2018-3620 [MEDIUM] Linux kernel (HWE) vulnerabilities
Title: Linux kernel (HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3740-1 fixed vulnerabilities in the Linux kernel for Ubuntu 18.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 18.04 LTS for Ubuntu
16.04 LTS.
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a malicious process that is executing on the CPU
core. This vulnerability is also known as L1 Terminal Fault (L1TF). A local
attacker in a guest virtual machine could use this to expose sensitive
information (memory from other guests or the host OS). (CVE-2018-3646)
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a malicious p
Debian
CVE-2018-5391: linux - The Linux kernel, versions 3.9+, is vulnerable to a denial of service attack wit...
vendor_debian·2018·CVSS 7.5
CVE-2018-5391 [HIGH] CVE-2018-5391: linux - The Linux kernel, versions 3.9+, is vulnerable to a denial of service attack wit...
The Linux kernel, versions 3.9+, is vulnerable to a denial of service attack with low rates of specially modified packets targeting IP fragment re-assembly. An attacker may cause a denial of service condition by sending specially crafted IP fragments. Various vulnerabilities in IP fragmentation have been discovered and fixed over the years. The current vulnerability (CVE-2018-5391) became exploitable in the Linux kernel with the increase of the IP fragment reassembly queue size.
Scope: local
bookworm: resolved (fixed in 4.17.15-1)
bullseye: resolved (fixed in 4.17.15-1)
forky: resolved (fixed in 4.17.15-1)
sid: resolved (fixed in 4.17.15-1)
trixie: resolved (fixed in 4.17.15-1)
Cisco
Linux Kernel IP Fragment Reassembly Denial of Service Vulnerability Affecting Cisco Products: August 2018
vendor_cisco
CVE-2018-5391 Linux Kernel IP Fragment Reassembly Denial of Service Vulnerability Affecting Cisco Products: August 2018
CVE-2018-5391: Linux Kernel IP Fragment Reassembly Denial of Service Vulnerability Affecting Cisco Products: August 2018
On August 14, 2018, the Vulnerability Coordination team of the National Cyber Security Centre of Finland (NCSC-FI) and the CERT Coordination Center (CERT/CC) disclosed a vulnerability in the IP stack that is used by the Linux Kernel. This vulnerability is publicly known as FragmentSmack . The vulnerability could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. An attack could be executed by an attacker who can submit a stream of fragmented IPv4 or IPv6 packets that are designed to trigger the issue on an affected device. The vulnerability is due to inefficient IPv4 and IPv6 fragment reassembly algorithms in the
GHSA
GHSA-p6x5-xg7h-fj5h: The Linux kernel, versions 3
ghsa_unreviewed·2022-05-14·CVSS 7.5
CVE-2018-5391 [HIGH] CWE-20 GHSA-p6x5-xg7h-fj5h: The Linux kernel, versions 3
The Linux kernel, versions 3.9+, is vulnerable to a denial of service attack with low rates of specially modified packets targeting IP fragment re-assembly. An attacker may cause a denial of service condition by sending specially crafted IP fragments. Various vulnerabilities in IP fragmentation have been discovered and fixed over the years. The current vulnerability (CVE-2018-5391) became exploitable in the Linux kernel with the increase of the IP fragment reassembly queue size.
OSV
CVE-2018-5391: The Linux kernel, versions 3
osv·2018-09-06·CVSS 7.5
CVE-2018-5391 [HIGH] CVE-2018-5391: The Linux kernel, versions 3
The Linux kernel, versions 3.9+, is vulnerable to a denial of service attack with low rates of specially modified packets targeting IP fragment re-assembly. An attacker may cause a denial of service condition by sending specially crafted IP fragments. Various vulnerabilities in IP fragmentation have been discovered and fixed over the years. The current vulnerability (CVE-2018-5391) became exploitable in the Linux kernel with the increase of the IP fragment reassembly queue size.
OSV
linux regressions
osv·2018-08-17·CVSS 5.6
CVE-2018-3620 [MEDIUM] linux regressions
linux regressions
USN-3741-1 introduced mitigations in the Linux kernel for Ubuntu 14.04
LTS to address L1 Terminal Fault (L1TF) vulnerabilities (CVE-2018-3620,
CVE-2018-3646). Unfortunately, the update introduced regressions
that caused kernel panics when booting in some environments as well
as preventing Java applications from starting. This update fixes
the problems.
We apologize for the inconvenience.
Original advisory details:
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a malicious process that is executing on the CPU
core. This vulnerability is also known as L1 Terminal Fault (L1TF). A local
attacker in a guest virtual machine could use this to expose sensitive
information (memory from other guests or the host OS). (CVE-2018-3
OSV
linux vulnerabilities
osv·2018-08-14·CVSS 5.5
CVE-2018-3646 [MEDIUM] linux vulnerabilities
linux vulnerabilities
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a malicious process that is executing on the CPU
core. This vulnerability is also known as L1 Terminal Fault (L1TF). A local
attacker in a guest virtual machine could use this to expose sensitive
information (memory from other guests or the host OS). (CVE-2018-3646)
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a malicious process that is executing on the CPU
core. This vulnerability is also known as L1 Terminal Fault (L1TF). A local
attacker could use this to expose sensitive information (memory from the
kernel or other processes). (CVE-2018-3620)
Andrey Konovalov discovered an out-of-bounds read in the POSIX
timers
OSV
linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
osv·2018-08-14·CVSS 5.6
CVE-2018-3646 [MEDIUM] linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a malicious process that is executing on the CPU
core. This vulnerability is also known as L1 Terminal Fault (L1TF). A local
attacker in a guest virtual machine could use this to expose sensitive
information (memory from other guests or the host OS). (CVE-2018-3646)
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a malicious process that is executing on the CPU
core. This vulnerability is also known as L1 Terminal Fault (L1TF). A local
attacker could use this to expose sensitive information (memory from the
kernel or other processes). (CVE-2018-3620)
Juha-Matti Tilli
OSV
linux, linux-aws, linux-azure, linux-gcp, linux-kvm, linux-oem, linux-raspi2 vulnerabilities
osv·2018-08-14·CVSS 5.6
CVE-2018-3646 [MEDIUM] linux, linux-aws, linux-azure, linux-gcp, linux-kvm, linux-oem, linux-raspi2 vulnerabilities
linux, linux-aws, linux-azure, linux-gcp, linux-kvm, linux-oem, linux-raspi2 vulnerabilities
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a malicious process that is executing on the CPU
core. This vulnerability is also known as L1 Terminal Fault (L1TF). A local
attacker in a guest virtual machine could use this to expose sensitive
information (memory from other guests or the host OS). (CVE-2018-3646)
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a malicious process that is executing on the CPU
core. This vulnerability is also known as L1 Terminal Fault (L1TF). A local
attacker could use this to expose sensitive information (memory from the
kernel or other processes). (CVE-2018-3620)
OSV
linux-hwe, linux-azure, linux-gcp vulnerabilities
osv·2018-08-14·CVSS 5.6
[MEDIUM] linux-hwe, linux-azure, linux-gcp vulnerabilities
linux-hwe, linux-azure, linux-gcp vulnerabilities
USN-3740-1 fixed vulnerabilities in the Linux kernel for Ubuntu 18.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 18.04 LTS for Ubuntu
16.04 LTS.
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a malicious process that is executing on the CPU
core. This vulnerability is also known as L1 Terminal Fault (L1TF). A local
attacker in a guest virtual machine could use this to expose sensitive
information (memory from other guests or the host OS). (CVE-2018-3646)
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a malicious process that is executing on the CPU
core. This vulnerabili
OSV
linux-lts-xenial, linux-aws vulnerabilities
osv·2018-08-14·CVSS 5.6
[MEDIUM] linux-lts-xenial, linux-aws vulnerabilities
linux-lts-xenial, linux-aws vulnerabilities
USN-3741-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 LTS.
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a malicious process that is executing on the CPU
core. This vulnerability is also known as L1 Terminal Fault (L1TF). A local
attacker in a guest virtual machine could use this to expose sensitive
information (memory from other guests or the host OS). (CVE-2018-3646)
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a malicious process that is executing on the CPU
core. This vulnerability is
VulnCheck
Linux Kernel Uncontrolled Resource Consumption
vulncheck·2018·CVSS 7.5
CVE-2018-5391 [HIGH] Linux Kernel Uncontrolled Resource Consumption
Linux Kernel Uncontrolled Resource Consumption
The Linux kernel, versions 3.9+, is vulnerable to a denial of service attack with low rates of specially modified packets targeting IP fragment re-assembly. An attacker may cause a denial of service condition by sending specially crafted IP fragments. Various vulnerabilities in IP fragmentation have been discovered and fixed over the years. The current vulnerability (CVE-2018-5391) became exploitable in the Linux kernel with the increase of the IP fragment reassembly queue size.
Affected: Linux Kernel
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Known Ransomware Campaign Use: Known
Exploitation References: https://www.csk.gov.in/
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-14641 kernel: a bug in ip_frag_reasm() can cause a crash in ip_do_fragment() [fedora-all]
bugzilla·2018-09-18·CVSS 6.5
CVE-2018-14641 [MEDIUM] CVE-2018-14641 kernel: a bug in ip_frag_reasm() can cause a crash in ip_do_fragment() [fedora-all]
CVE-2018-14641 kernel: a bug in ip_frag_reasm() can cause a crash in ip_do_fragment() [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multip
Bugzilla
CVE-2018-14641 CVE-2018-5391 kernel: various flaws [fedora-all]
bugzilla·2018-08-14·CVSS 6.5
CVE-2018-14641 [MEDIUM] CVE-2018-14641 CVE-2018-5391 kernel: various flaws [fedora-all]
CVE-2018-14641 CVE-2018-5391 kernel: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. Wh
Bugzilla
CVE-2018-5391 kernel: IP fragments with random offsets allow a remote denial of service (FragmentSmack)
bugzilla·2018-07-30·CVSS 7.5
CVE-2018-5391 [HIGH] CVE-2018-5391 kernel: IP fragments with random offsets allow a remote denial of service (FragmentSmack)
CVE-2018-5391 kernel: IP fragments with random offsets allow a remote denial of service (FragmentSmack)
A flaw named FragmentSmack was found in the way the Linux kernel handled reassembly of fragmented IPv4 and IPv6 packets. A remote attacker could use this flaw to trigger time and calculation expensive fragment reassembly algorithms by sending specially crafted packets which could lead to a CPU saturation and hence a denial of service on the system.
External References:
https://access.redhat.com/articles/3553061
https://www.kb.cert.org/vuls/id/641765
A fix is a merge commit in the Linux kernel tree:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=c30f1fc041b74ecdb072dd44f858750414b8b19f
consisting of the following commits:
7969e5c40dfd04799d4341f1b7cd
http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2018-004.txthttp://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200115-01-linux-enhttp://www.openwall.com/lists/oss-security/2019/06/28/2http://www.openwall.com/lists/oss-security/2019/07/06/3http://www.openwall.com/lists/oss-security/2019/07/06/4http://www.securityfocus.com/bid/105108http://www.securitytracker.com/id/1041476http://www.securitytracker.com/id/1041637https://access.redhat.com/errata/RHSA-2018:2785https://access.redhat.com/errata/RHSA-2018:2791https://access.redhat.com/errata/RHSA-2018:2846https://access.redhat.com/errata/RHSA-2018:2924https://access.redhat.com/errata/RHSA-2018:2925https://access.redhat.com/errata/RHSA-2018:2933https://access.redhat.com/errata/RHSA-2018:2948https://access.redhat.com/errata/RHSA-2018:3083https://access.redhat.com/errata/RHSA-2018:3096https://access.redhat.com/errata/RHSA-2018:3459https://access.redhat.com/errata/RHSA-2018:3540https://access.redhat.com/errata/RHSA-2018:3586https://access.redhat.com/errata/RHSA-2018:3590https://cert-portal.siemens.com/productcert/pdf/ssa-377115.pdfhttps://git.kernel.org/pub/scm/linux/kernel/git/davem/net-next.git/commit/?id=c30f1fc041b74ecdb072dd44f858750414b8b19fhttps://lists.debian.org/debian-lts-announce/2018/08/msg00014.htmlhttps://lists.debian.org/debian-lts-announce/2019/03/msg00017.htmlhttps://security.netapp.com/advisory/ntap-20181003-0002/https://support.f5.com/csp/article/K74374841?utm_source=f5support&%3Butm_medium=RSShttps://usn.ubuntu.com/3740-1/https://usn.ubuntu.com/3740-2/https://usn.ubuntu.com/3741-1/https://usn.ubuntu.com/3741-2/https://usn.ubuntu.com/3742-1/https://usn.ubuntu.com/3742-2/https://www.debian.org/security/2018/dsa-4272https://www.kb.cert.org/vuls/id/641765http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2018-004.txthttp://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200115-01-linux-enhttp://www.openwall.com/lists/oss-security/2019/06/28/2http://www.openwall.com/lists/oss-security/2019/07/06/3http://www.openwall.com/lists/oss-security/2019/07/06/4http://www.securityfocus.com/bid/105108http://www.securitytracker.com/id/1041476http://www.securitytracker.com/id/1041637https://access.redhat.com/errata/RHSA-2018:2785https://access.redhat.com/errata/RHSA-2018:2791https://access.redhat.com/errata/RHSA-2018:2846https://access.redhat.com/errata/RHSA-2018:2924https://access.redhat.com/errata/RHSA-2018:2925https://access.redhat.com/errata/RHSA-2018:2933https://access.redhat.com/errata/RHSA-2018:2948https://access.redhat.com/errata/RHSA-2018:3083https://access.redhat.com/errata/RHSA-2018:3096https://access.redhat.com/errata/RHSA-2018:3459https://access.redhat.com/errata/RHSA-2018:3540https://access.redhat.com/errata/RHSA-2018:3586https://access.redhat.com/errata/RHSA-2018:3590https://cert-portal.siemens.com/productcert/pdf/ssa-377115.pdfhttps://git.kernel.org/pub/scm/linux/kernel/git/davem/net-next.git/commit/?id=c30f1fc041b74ecdb072dd44f858750414b8b19fhttps://lists.debian.org/debian-lts-announce/2018/08/msg00014.htmlhttps://lists.debian.org/debian-lts-announce/2019/03/msg00017.htmlhttps://security.netapp.com/advisory/ntap-20181003-0002/https://support.f5.com/csp/article/K74374841?utm_source=f5support&%3Butm_medium=RSShttps://usn.ubuntu.com/3740-1/https://usn.ubuntu.com/3740-2/https://usn.ubuntu.com/3741-1/https://usn.ubuntu.com/3741-2/https://usn.ubuntu.com/3742-1/https://usn.ubuntu.com/3742-2/https://www.debian.org/security/2018/dsa-4272https://www.kb.cert.org/vuls/id/641765
2018-09-06
Published
Exploited in the wild