CVE-2018-5391
06.09.2018, 21:29
The Linux kernel, versions 3.9+, is vulnerable to a denial of service attack with low rates of specially modified packets targeting IP fragment re-assembly. An attacker may cause a denial of service condition by sending specially crafted IP fragments. Various vulnerabilities in IP fragmentation have been discovered and fixed over the years. The current vulnerability (CVE-2018-5391) became exploitable in the Linux kernel with the increase of the IP fragment reassembly queue size.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| linux | linux_kernel | 3.9 ≤ 𝑥 ≤ 4.18 |
| redhat | enterprise_linux_desktop | 6.0 |
| redhat | enterprise_linux_desktop | 7.0 |
| redhat | enterprise_linux_server | 6.0 |
| redhat | enterprise_linux_server | 7.0 |
| redhat | enterprise_linux_server_aus | 6.4 |
| redhat | enterprise_linux_server_aus | 6.5 |
| redhat | enterprise_linux_server_aus | 6.6 |
| redhat | enterprise_linux_server_aus | 7.2 |
| redhat | enterprise_linux_server_aus | 7.3 |
| redhat | enterprise_linux_server_aus | 7.4 |
| redhat | enterprise_linux_server_eus | 6.7 |
| redhat | enterprise_linux_server_eus | 7.3 |
| redhat | enterprise_linux_server_eus | 7.4 |
| redhat | enterprise_linux_server_eus | 7.5 |
| redhat | enterprise_linux_server_tus | 6.6 |
| redhat | enterprise_linux_server_tus | 7.2 |
| redhat | enterprise_linux_server_tus | 7.3 |
| redhat | enterprise_linux_server_tus | 7.4 |
| redhat | enterprise_linux_workstation | 6.0 |
| redhat | enterprise_linux_workstation | 7.0 |
| debian | debian_linux | 8.0 |
| debian | debian_linux | 9.0 |
| canonical | ubuntu_linux | 12.04 |
| canonical | ubuntu_linux | 14.04 |
| canonical | ubuntu_linux | 16.04 |
| canonical | ubuntu_linux | 18.04 |
| microsoft | windows_10 | - |
| microsoft | windows_7 | - |
| microsoft | windows_8.1 | - |
| microsoft | windows_rt_8.1 | - |
| microsoft | windows_server_2008 | - |
| microsoft | windows_server_2012 | - |
| microsoft | windows_server_2016 | - |
| f5 | big-ip_access_policy_manager | 11.5.1 ≤ 𝑥 < 11.6.5.1 |
| f5 | big-ip_access_policy_manager | 12.1.0 ≤ 𝑥 < 12.1.5 |
| f5 | big-ip_access_policy_manager | 13.0.0 ≤ 𝑥 < 13.1.3 |
| f5 | big-ip_access_policy_manager | 14.0.0 ≤ 𝑥 < 14.0.1.1 |
| f5 | big-ip_access_policy_manager | 14.1.0 ≤ 𝑥 < 14.1.2.4 |
| f5 | big-ip_advanced_firewall_manager | 11.5.1 ≤ 𝑥 < 11.6.5.1 |
| f5 | big-ip_advanced_firewall_manager | 12.1.0 ≤ 𝑥 < 12.1.5 |
| f5 | big-ip_advanced_firewall_manager | 13.0.0 ≤ 𝑥 < 13.1.3 |
| f5 | big-ip_advanced_firewall_manager | 14.0.0 ≤ 𝑥 < 14.0.1.1 |
| f5 | big-ip_advanced_firewall_manager | 14.1.0 ≤ 𝑥 < 14.1.2.4 |
| f5 | big-ip_analytics | 11.5.1 ≤ 𝑥 < 11.6.5.1 |
| f5 | big-ip_analytics | 12.1.0 ≤ 𝑥 < 12.1.5 |
| f5 | big-ip_analytics | 13.0.0 ≤ 𝑥 < 13.1.3 |
| f5 | big-ip_analytics | 14.0.0 ≤ 𝑥 < 14.0.1.1 |
| f5 | big-ip_analytics | 14.1.0 ≤ 𝑥 < 14.1.2.4 |
| f5 | big-ip_application_acceleration_manager | 11.5.1 ≤ 𝑥 < 11.6.5.1 |
| f5 | big-ip_application_acceleration_manager | 12.1.0 ≤ 𝑥 < 12.1.5 |
| f5 | big-ip_application_acceleration_manager | 13.0.0 ≤ 𝑥 < 13.1.3 |
| f5 | big-ip_application_acceleration_manager | 14.0.0 ≤ 𝑥 < 14.0.1.1 |
| f5 | big-ip_application_acceleration_manager | 14.1.0 ≤ 𝑥 < 14.1.2.4 |
| f5 | big-ip_application_security_manager | 11.5.1 ≤ 𝑥 < 11.6.5.1 |
| f5 | big-ip_application_security_manager | 12.1.0 ≤ 𝑥 < 12.1.5 |
| f5 | big-ip_application_security_manager | 13.0.0 ≤ 𝑥 < 13.1.3 |
| f5 | big-ip_application_security_manager | 14.0.0 ≤ 𝑥 < 14.0.1.1 |
| f5 | big-ip_application_security_manager | 14.1.0 ≤ 𝑥 < 14.1.2.4 |
| f5 | big-ip_domain_name_system | 11.5.1 ≤ 𝑥 < 11.6.5.1 |
| f5 | big-ip_domain_name_system | 12.1.0 ≤ 𝑥 < 12.1.5 |
| f5 | big-ip_domain_name_system | 13.0.0 ≤ 𝑥 < 13.1.3 |
| f5 | big-ip_domain_name_system | 14.0.0 ≤ 𝑥 < 14.0.1.1 |
| f5 | big-ip_domain_name_system | 14.1.0 ≤ 𝑥 < 14.1.2.4 |
| f5 | big-ip_edge_gateway | 11.5.1 ≤ 𝑥 < 11.6.5.1 |
| f5 | big-ip_edge_gateway | 12.1.0 ≤ 𝑥 < 12.1.5 |
| f5 | big-ip_edge_gateway | 13.0.0 ≤ 𝑥 < 13.1.3 |
| f5 | big-ip_edge_gateway | 14.0.0 ≤ 𝑥 < 14.0.1.1 |
| f5 | big-ip_edge_gateway | 14.1.0 ≤ 𝑥 < 14.1.2.4 |
| f5 | big-ip_fraud_protection_service | 11.5.1 ≤ 𝑥 < 11.6.5.1 |
| f5 | big-ip_fraud_protection_service | 12.1.0 ≤ 𝑥 < 12.1.5 |
| f5 | big-ip_fraud_protection_service | 13.0.0 ≤ 𝑥 < 13.1.3 |
| f5 | big-ip_fraud_protection_service | 14.0.0 ≤ 𝑥 < 14.0.1.1 |
| f5 | big-ip_fraud_protection_service | 14.1.0 ≤ 𝑥 < 14.1.2.4 |
| f5 | big-ip_global_traffic_manager | 11.5.1 ≤ 𝑥 < 11.6.5.1 |
| f5 | big-ip_global_traffic_manager | 12.1.0 ≤ 𝑥 < 12.1.5 |
| f5 | big-ip_global_traffic_manager | 13.0.0 ≤ 𝑥 < 13.1.3 |
| f5 | big-ip_global_traffic_manager | 14.0.0 ≤ 𝑥 < 14.0.1.1 |
| f5 | big-ip_global_traffic_manager | 14.1.0 ≤ 𝑥 < 14.1.2.4 |
| f5 | big-ip_link_controller | 11.5.1 ≤ 𝑥 < 11.6.5.1 |
| f5 | big-ip_link_controller | 12.1.0 ≤ 𝑥 < 12.1.5 |
| f5 | big-ip_link_controller | 13.0.0 ≤ 𝑥 < 13.1.3 |
| f5 | big-ip_link_controller | 14.0.0 ≤ 𝑥 < 14.0.1.1 |
| f5 | big-ip_link_controller | 14.1.0 ≤ 𝑥 < 14.1.2.4 |
| f5 | big-ip_local_traffic_manager | 11.5.1 ≤ 𝑥 < 11.6.5.1 |
| f5 | big-ip_local_traffic_manager | 12.1.0 ≤ 𝑥 < 12.1.5 |
| f5 | big-ip_local_traffic_manager | 13.0.0 ≤ 𝑥 < 13.1.3 |
| f5 | big-ip_local_traffic_manager | 14.0.0 ≤ 𝑥 < 14.0.1.1 |
| f5 | big-ip_local_traffic_manager | 14.1.0 ≤ 𝑥 < 14.1.2.4 |
| f5 | big-ip_policy_enforcement_manager | 11.5.1 ≤ 𝑥 < 11.6.5.1 |
| f5 | big-ip_policy_enforcement_manager | 12.1.0 ≤ 𝑥 < 12.1.5 |
| f5 | big-ip_policy_enforcement_manager | 13.0.0 ≤ 𝑥 < 13.1.3 |
| f5 | big-ip_policy_enforcement_manager | 14.0.0 ≤ 𝑥 < 14.0.1.1 |
| f5 | big-ip_policy_enforcement_manager | 14.1.0 ≤ 𝑥 < 14.1.2.4 |
| f5 | big-ip_webaccelerator | 11.5.1 ≤ 𝑥 < 11.6.5.1 |
| f5 | big-ip_webaccelerator | 12.1.0 ≤ 𝑥 < 12.1.5 |
| f5 | big-ip_webaccelerator | 13.0.0 ≤ 𝑥 < 13.1.3 |
| f5 | big-ip_webaccelerator | 14.0.0 ≤ 𝑥 < 14.0.1.1 |
| f5 | big-ip_webaccelerator | 14.1.0 ≤ 𝑥 < 14.1.2.4 |
| siemens | ruggedcom_rm1224_firmware | 𝑥 < 6.1 |
| siemens | ruggedcom_rox_ii_firmware | 𝑥 < 2.13.3 |
| siemens | scalance_m-800_firmware | 𝑥 < 6.1 |
| siemens | scalance_s615_firmware | 𝑥 < 6.1 |
| siemens | scalance_sc-600_firmware | 𝑥 < 2.0 |
| siemens | scalance_w1700_ieee_802.11ac_firmware | 𝑥 < 2.0 |
| siemens | scalance_w700_ieee_802.11a\/b\/g\/n_firmware | 𝑥 < 6.4 |
| siemens | simatic_net_cp_1242-7_firmware | 𝑥 < 3.2 |
| siemens | simatic_net_cp_1243-1_firmware | 𝑥 < 3.2 |
| siemens | simatic_net_cp_1243-7_lte_eu_firmware | 𝑥 < 3.2 |
| siemens | simatic_net_cp_1243-7_lte_us_firmware | 𝑥 < 3.2 |
| siemens | simatic_net_cp_1243-8_irc_firmware | 𝑥 < 3.2 |
| siemens | simatic_net_cp_1542sp-1_firmware | 𝑥 < 2.1 |
| siemens | simatic_net_cp_1542sp-1_irc_firmware | 𝑥 < 2.1 |
| siemens | simatic_net_cp_1543-1_firmware | 𝑥 < 2.2 |
| siemens | simatic_net_cp_1543sp-1_firmware | 𝑥 < 2.1 |
| siemens | simatic_rf185c_firmware | 𝑥 < 1.3 |
| siemens | simatic_rf186c_firmware | 𝑥 < 1.3 |
| siemens | simatic_rf186ci_firmware | 𝑥 < 1.3 |
| siemens | simatic_rf188_firmware | 𝑥 < 1.3 |
| siemens | simatic_rf188ci_firmware | 𝑥 < 1.3 |
| siemens | sinema_remote_connect_server_firmware | 1.1 ≤ 𝑥 < 2.0.1 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||
|---|---|---|---|---|---|---|---|---|---|
| linux |
| ||||||||
| linux-aws |
| ||||||||
| linux-azure |
| ||||||||
| linux-azure-edge |
| ||||||||
| linux-euclid |
| ||||||||
| linux-flo |
| ||||||||
| linux-gcp |
| ||||||||
| linux-gke |
| ||||||||
| linux-goldfish |
| ||||||||
| linux-grouper |
| ||||||||
| linux-hwe |
| ||||||||
| linux-hwe-edge |
| ||||||||
| linux-kvm |
| ||||||||
| linux-lts-trusty |
| ||||||||
| linux-lts-utopic |
| ||||||||
| linux-lts-vivid |
| ||||||||
| linux-lts-wily |
| ||||||||
| linux-lts-xenial |
| ||||||||
| linux-maguro |
| ||||||||
| linux-mako |
| ||||||||
| linux-manta |
| ||||||||
| linux-oem |
| ||||||||
| linux-raspi2 |
| ||||||||
| linux-snapdragon |
|
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| kernel-azure |
| ||||||||||||||||||||
| kernel-azure-base |
| ||||||||||||||||||||
| kernel-default |
| ||||||||||||||||||||
| kernel-default-base |
| ||||||||||||||||||||
| kernel-default-man |
| ||||||||||||||||||||
| kernel-docs |
| ||||||||||||||||||||
| kernel-ec2 |
| ||||||||||||||||||||
| kernel-ec2-extra |
| ||||||||||||||||||||
| kernel-macros |
| ||||||||||||||||||||
| kernel-obs-build |
| ||||||||||||||||||||
| kernel-source |
| ||||||||||||||||||||
| kernel-source-azure |
| ||||||||||||||||||||
| kernel-syms |
| ||||||||||||||||||||
| kernel-syms-azure |
| ||||||||||||||||||||
| kernel-vanilla-base |
| ||||||||||||||||||||
| kernel-xen |
| ||||||||||||||||||||
| kernel-xen-base |
| ||||||||||||||||||||
| kernel-zfcpdump |
| ||||||||||||||||||||
| kgraft-patch-3_12_61-52_125-default-12 |
| ||||||||||||||||||||
| kgraft-patch-3_12_61-52_125-xen-12 |
| ||||||||||||||||||||
| kgraft-patch-3_12_61-52_128-default-10 |
| ||||||||||||||||||||
| kgraft-patch-3_12_61-52_128-xen-10 |
| ||||||||||||||||||||
| kgraft-patch-3_12_61-52_133-default-9 |
| ||||||||||||||||||||
| kgraft-patch-3_12_61-52_133-xen-9 |
| ||||||||||||||||||||
| kgraft-patch-3_12_61-52_136-default-9 |
| ||||||||||||||||||||
| kgraft-patch-3_12_61-52_136-xen-9 |
| ||||||||||||||||||||
| kgraft-patch-3_12_61-52_141-default-8 |
| ||||||||||||||||||||
| kgraft-patch-3_12_61-52_141-xen-8 |
| ||||||||||||||||||||
| kgraft-patch-3_12_61-52_146-default-6 |
| ||||||||||||||||||||
| kgraft-patch-3_12_61-52_146-xen-6 |
| ||||||||||||||||||||
| kgraft-patch-3_12_61-52_149-default-1 |
| ||||||||||||||||||||
| kgraft-patch-3_12_61-52_149-xen-1 |
| ||||||||||||||||||||
| kgraft-patch-3_12_74-60_64_104-default-6 |
| ||||||||||||||||||||
| kgraft-patch-3_12_74-60_64_104-xen-6 |
| ||||||||||||||||||||
| kgraft-patch-3_12_74-60_64_107-default-6 |
| ||||||||||||||||||||
| kgraft-patch-3_12_74-60_64_107-xen-6 |
| ||||||||||||||||||||
| kgraft-patch-3_12_74-60_64_110-default-1 |
| ||||||||||||||||||||
| kgraft-patch-3_12_74-60_64_110-xen-1 |
| ||||||||||||||||||||
| kgraft-patch-3_12_74-60_64_85-default-12 |
| ||||||||||||||||||||
| kgraft-patch-3_12_74-60_64_85-xen-12 |
| ||||||||||||||||||||
| kgraft-patch-3_12_74-60_64_88-default-10 |
| ||||||||||||||||||||
| kgraft-patch-3_12_74-60_64_88-xen-10 |
| ||||||||||||||||||||
| kgraft-patch-3_12_74-60_64_93-default-9 |
| ||||||||||||||||||||
| kgraft-patch-3_12_74-60_64_93-xen-9 |
| ||||||||||||||||||||
| kgraft-patch-3_12_74-60_64_96-default-9 |
| ||||||||||||||||||||
| kgraft-patch-3_12_74-60_64_96-xen-9 |
| ||||||||||||||||||||
| kgraft-patch-3_12_74-60_64_99-default-8 |
| ||||||||||||||||||||
| kgraft-patch-3_12_74-60_64_99-xen-8 |
| ||||||||||||||||||||
| kgraft-patch-4_4_103-92_53-default-11 |
| ||||||||||||||||||||
| kgraft-patch-4_4_103-92_56-default-11 |
| ||||||||||||||||||||
| kgraft-patch-4_4_114-92_64-default-9 |
| ||||||||||||||||||||
| kgraft-patch-4_4_114-92_67-default-9 |
| ||||||||||||||||||||
| kgraft-patch-4_4_120-92_70-default-8 |
| ||||||||||||||||||||
| kgraft-patch-4_4_121-92_73-default-7 |
| ||||||||||||||||||||
| kgraft-patch-4_4_121-92_80-default-7 |
| ||||||||||||||||||||
| kgraft-patch-4_4_121-92_85-default-5 |
| ||||||||||||||||||||
| kgraft-patch-4_4_121-92_92-default-1 |
| ||||||||||||||||||||
| kgraft-patch-4_4_90-92_50-default-12 |
| ||||||||||||||||||||
| lttng-modules |
|
Red Hat Enterprise Linux Releases
Red Hat Product | |||||
|---|---|---|---|---|---|
| bpftool |
| ||||
| kernel |
| ||||
| kernel-abi-whitelists |
| ||||
| kernel-bootwrapper |
| ||||
| kernel-debug |
| ||||
| kernel-debug-devel |
| ||||
| kernel-devel |
| ||||
| kernel-doc |
| ||||
| kernel-firmware |
| ||||
| kernel-headers |
| ||||
| kernel-kdump |
| ||||
| kernel-kdump-devel |
| ||||
| kernel-rt |
| ||||
| kernel-rt-debug |
| ||||
| kernel-rt-debug-devel |
| ||||
| kernel-rt-debug-kvm |
| ||||
| kernel-rt-devel |
| ||||
| kernel-rt-doc |
| ||||
| kernel-rt-kvm |
| ||||
| kernel-rt-trace |
| ||||
| kernel-rt-trace-devel |
| ||||
| kernel-rt-trace-kvm |
| ||||
| kernel-tools |
| ||||
| kernel-tools-libs |
| ||||
| kernel-tools-libs-devel |
| ||||
| perf |
| ||||
| python-perf |
|
Common Weakness Enumeration
- CWE-400 - Uncontrolled Resource ConsumptionThe software does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.
- CWE-20 - Improper Input ValidationThe product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
References