Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can lead to a denial of service.
Project Subscriptions
| Vendors | Products |
|---|---|
|
A10networks
Subscribe
|
Advanced Core Operating System
Subscribe
|
|
Canonical
Subscribe
|
Ubuntu Linux
Subscribe
|
|
Cisco
Subscribe
|
Collaboration Meeting Rooms
Subscribe
Digital Network Architecture Center
Subscribe
Expressway
Subscribe
Expressway Series
Subscribe
Meeting Management
Subscribe
Network Assurance Engine
Subscribe
Telepresence Conductor
Subscribe
Telepresence Conductor Firmware
Subscribe
Telepresence Video Communication Server
Subscribe
Telepresence Video Communication Server Firmware
Subscribe
Threat Grid-cloud
Subscribe
Webex Hybrid Data Security
Subscribe
Webex Video Mesh
Subscribe
|
|
Debian
Subscribe
|
Debian Linux
Subscribe
|
|
F5
Subscribe
|
Big-ip Access Policy Manager
Subscribe
Big-ip Advanced Firewall Manager
Subscribe
Big-ip Analytics
Subscribe
Big-ip Application Acceleration Manager
Subscribe
Big-ip Application Security Manager
Subscribe
Big-ip Domain Name System
Subscribe
Big-ip Edge Gateway
Subscribe
Big-ip Fraud Protection Service
Subscribe
Big-ip Global Traffic Manager
Subscribe
Big-ip Link Controller
Subscribe
Big-ip Local Traffic Manager
Subscribe
Big-ip Policy Enforcement Manager
Subscribe
Big-ip Webaccelerator
Subscribe
Traffix Systems Signaling Delivery Controller
Subscribe
|
|
Hp
Subscribe
|
|
|
Linux
Subscribe
|
Linux Kernel
Subscribe
|
|
Redhat
Subscribe
|
Enterprise Linux
Subscribe
Enterprise Linux Desktop
Subscribe
Enterprise Linux Server
Subscribe
Enterprise Linux Server Aus
Subscribe
Enterprise Linux Server Eus
Subscribe
Enterprise Linux Server Tus
Subscribe
Enterprise Linux Workstation
Subscribe
Enterprise Mrg
Subscribe
Rhel Aus
Subscribe
Rhel E4s
Subscribe
Rhel Eus
Subscribe
Rhel Extras Rt
Subscribe
Rhel Tus
Subscribe
Virtualization
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1466-1 | linux-4.9 security update |
Debian DSA |
DSA-4266-1 | linux security update |
Ubuntu USN |
USN-3732-1 | Linux kernel vulnerability |
Ubuntu USN |
USN-3732-2 | Linux kernel (HWE) vulnerability |
Ubuntu USN |
USN-3741-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-3741-2 | Linux kernel (Xenial HWE) vulnerabilities |
Ubuntu USN |
USN-3742-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-3742-2 | Linux kernel (Trusty HWE) vulnerabilities |
Ubuntu USN |
USN-3763-1 | Linux kernel vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2024-08-05T05:33:44.409Z
Reserved: 2018-01-12T00:00:00
Link: CVE-2018-5390
No data.
Status : Modified
Published: 2018-08-06T20:29:01.570
Modified: 2024-11-21T04:08:43.610
Link: CVE-2018-5390
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Debian DSA
Ubuntu USN