UBUNTU-CVE-2018-5391
Dashboard / Vulnerabilities / UBUNTU-CVE-2018-5391
UBUNTU-CVE-2018-5391
Summary:
Details: The Linux kernel, versions 3.9+, is vulnerable to a denial of service attack with low rates of specially modified packets targeting IP fragment re-assembly. An attacker may cause a denial of service condition by sending specially crafted IP fragments. Various vulnerabilities in IP fragmentation have been discovered and fixed over the years. The current vulnerability (CVE-2018-5391) became exploitable in the Linux kernel with the increase of the IP fragment reassembly queue size.
References: https://ubuntu.com/security/CVE-2018-5391, https://www.kb.cert.org/vuls/id/641765, https://ubuntu.com/security/notices/USN-3740-1, https://ubuntu.com/security/notices/USN-3740-2, https://ubuntu.com/security/notices/USN-3741-1, https://ubuntu.com/security/notices/USN-3741-2, https://ubuntu.com/security/notices/USN-3742-1, https://ubuntu.com/security/notices/USN-3742-2, https://www.cve.org/CVERecord?id=CVE-2018-5391
Affected packages
Package
Name: linux
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
