Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can lead to a denial of service
Published Aug 6, 2018
7.5
HIGHCVSS 3.1
EPSS 73.72%
Description
Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can lead to a denial of service.
Affected products
-
- Version 4.9StatusaffectedConstraints<4.9*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux Kernel | n/a |
|
Configuration 1
- 4.0
- 7.0
- 7.0
- 6.4
- 6.5
- 6.6
- 7.2
- 7.3
- 7.4
- 6.4
- 6.7
- 7.2
- 7.3
- 7.4
- 7.5
- 6.6
- 7.2
- 7.3
- 7.4
- 7.0
Configuration 2
- ≥ 4.9 · < 4.18
- 4.18
- 4.18
- 4.18
- 4.18
- 4.18
- 4.18
Configuration 3
- 12.04
- 14.04
- 16.04
- 18.04
Configuration 4
- 8.0
- 9.0
Configuration 5
- < 8.2.7.1
- ≥ 6.6.0 · ≤ 6.6.9
- ≥ 6.7.0 · ≤ 6.7.5
Configuration 6
- ≥ 11.5.1 · ≤ 11.6.3
- ≥ 12.1.0 · ≤ 12.1.3
- ≥ 13.0.0 · ≤ 13.1.1
- 14.0.0
- ≥ 11.5.1 · ≤ 11.6.3
- ≥ 12.1.0 · ≤ 12.1.3
- ≥ 13.0.0 · ≤ 13.1.1
- 14.0.0
- ≥ 11.5.1 · ≤ 11.6.3
- ≥ 12.1.0 · ≤ 12.1.3
- ≥ 13.0.0 · ≤ 13.1.1
- 14.0.0
- ≥ 11.5.1 · ≤ 11.6.3
- ≥ 12.1.0 · ≤ 12.1.3
- ≥ 13.0.0 · ≤ 13.1.1
- 14.0.0
- ≥ 11.5.1 · ≤ 11.6.3
- ≥ 12.1.0 · ≤ 12.1.3
- ≥ 13.0.0 · ≤ 13.1.1
- 14.0.0
- ≥ 11.5.1 · ≤ 11.6.3
- ≥ 12.1.0 · ≤ 12.1.3
- ≥ 13.0.0 · ≤ 13.1.1
- 14.0.0
- ≥ 11.5.1. · ≤ 11.6.3
- ≥ 12.1.0 · ≤ 12.1.3
- ≥ 13.0.0 · ≤ 13.1.1
- 14.0.0
- ≥ 11.5.1 · ≤ 11.6.3
- ≥ 12.1.0 · ≤ 12.1.3
- ≥ 13.0.0 · ≤ 13.1.1
- 14.0.0
- ≥ 11.5.1 · ≤ 11.6.3
- ≥ 12.1.0 · ≤ 12.1.3
- ≥ 13.0.0 · ≤ 13.1.1
- 14.0.0
- ≥ 11.5.1 · ≤ 11.6.3
- ≥ 12.1.0 · ≤ 12.1.3
- ≥ 13.0.0 · ≤ 13.1.1
- 14.0.0
- ≥ 11.5.1 · ≤ 11.6.3
- ≥ 12.0.0 · ≤ 12.1.3
- > 13.0.0 · ≤ 13.1.1
- 14.0.0
- ≥ 11.5.1 · ≤ 11.6.3
- ≥ 12.1.0 · ≤ 12.1.3
- ≥ 13.0.0 · ≤ 13.1.1
- 14.0.0
- ≥ 11.5.1 · ≤ 11.6.3
- ≥ 12.1.0 · ≤ 12.1.3
- ≥ 13.0.0 · ≤ 13.1.1
- 14.0.0
- ≥ 5.0.0 · ≤ 5.1.0
- 4.4.0
Configuration 7
- 3.2.2
- 3.2.2
- 4.1.0
- 4.1.0
- 4.1.1
- 4.1.2
- 4.1.2
- 4.1.4
- 4.1.4
Configuration 8
- 1.0
- 1.2
- x8.10
- x8.10.1
- x8.10.2
- x8.10.3
- x8.10.4
- x8.11
- n/a
- 1.0
- 1.0.1
- 2.1\(1a\)
- n/a
- n/a
- n/a
Configuration 9
- x8.10
- x8.10.1
- x8.10.2
- x8.10.3
- x8.10.4
- x8.11
Running on/with
- n/a
Configuration 10
- xc4.3
- xc4.3.1
- xc4.3.2
- xc4.3.3
- xc4.3.4
Running on/with
- n/a
No data.
Red Hat Enterprise Linux 6
kernel-0:2.6.32-754.3.5.el6
Fixed · RHSA-2018:2390
Red Hat Enterprise Linux 6.4 Advanced Update Support
kernel-0:2.6.32-358.93.1.el6
Fixed · RHSA-2018:2791
Red Hat Enterprise Linux 6.5 Advanced Update Support
kernel-0:2.6.32-431.93.2.el6
Fixed · RHSA-2018:2933
Red Hat Enterprise Linux 6.6 Advanced Update Support
kernel-0:2.6.32-504.76.2.el6
Fixed · RHSA-2018:2924
Red Hat Enterprise Linux 6.6 Telco Extended Update Support
kernel-0:2.6.32-504.76.2.el6
Fixed · RHSA-2018:2924
Red Hat Enterprise Linux 6.7 Extended Update Support
kernel-0:2.6.32-573.62.1.el6
Fixed · RHSA-2018:2645
Red Hat Enterprise Linux 7
kernel-0:3.10.0-862.11.6.el7
Fixed · RHSA-2018:2384
Red Hat Enterprise Linux 7
kernel-alt-0:4.14.0-115.el7a
Fixed · RHSA-2018:2948
Red Hat Enterprise Linux 7
kernel-rt-0:3.10.0-862.11.6.rt56.819.el7
Fixed · RHSA-2018:2395
Red Hat Enterprise Linux 7.2 Advanced Update Support
kernel-0:3.10.0-327.73.1.el7
Fixed · RHSA-2018:2790
Red Hat Enterprise Linux 7.2 Telco Extended Update Support
kernel-0:3.10.0-327.73.1.el7
Fixed · RHSA-2018:2790
Red Hat Enterprise Linux 7.2 Update Services for SAP Solutions
kernel-0:3.10.0-327.73.1.el7
Fixed · RHSA-2018:2790
Red Hat Enterprise Linux 7.3 Extended Update Support
kernel-0:3.10.0-514.58.1.el7
Fixed · RHSA-2018:2785
Red Hat Enterprise Linux 7.4 Extended Update Support
kernel-0:3.10.0-693.39.1.el7
Fixed · RHSA-2018:2776
Red Hat Enterprise MRG 2
kernel-rt-1:3.10.0-693.39.1.rt56.629.el6rt
Fixed · RHSA-2018:2789
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7
redhat-release-virtualization-host-0:4.2-5.2.el7
Fixed · RHSA-2018:2403
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7
redhat-virtualization-host-0:4.2-20180813.0
Fixed · RHSA-2018:2403
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7
rhvm-appliance-0:4.2-20180813.0
Fixed · RHSA-2018:2402
Red Hat Enterprise Linux 5
kernel
Will not fix
Red Hat Enterprise Linux 8
kernel
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel-0:2.6.32-754.3.5.el6 | Fixed | RHSA-2018:2390 |
| Red Hat Enterprise Linux 6.4 Advanced Update Support | kernel-0:2.6.32-358.93.1.el6 | Fixed | RHSA-2018:2791 |
| Red Hat Enterprise Linux 6.5 Advanced Update Support | kernel-0:2.6.32-431.93.2.el6 | Fixed | RHSA-2018:2933 |
| Red Hat Enterprise Linux 6.6 Advanced Update Support | kernel-0:2.6.32-504.76.2.el6 | Fixed | RHSA-2018:2924 |
| Red Hat Enterprise Linux 6.6 Telco Extended Update Support | kernel-0:2.6.32-504.76.2.el6 | Fixed | RHSA-2018:2924 |
| Red Hat Enterprise Linux 6.7 Extended Update Support | kernel-0:2.6.32-573.62.1.el6 | Fixed | RHSA-2018:2645 |
| Red Hat Enterprise Linux 7 | kernel-0:3.10.0-862.11.6.el7 | Fixed | RHSA-2018:2384 |
| Red Hat Enterprise Linux 7 | kernel-alt-0:4.14.0-115.el7a | Fixed | RHSA-2018:2948 |
| Red Hat Enterprise Linux 7 | kernel-rt-0:3.10.0-862.11.6.rt56.819.el7 | Fixed | RHSA-2018:2395 |
| Red Hat Enterprise Linux 7.2 Advanced Update Support | kernel-0:3.10.0-327.73.1.el7 | Fixed | RHSA-2018:2790 |
| Red Hat Enterprise Linux 7.2 Telco Extended Update Support | kernel-0:3.10.0-327.73.1.el7 | Fixed | RHSA-2018:2790 |
| Red Hat Enterprise Linux 7.2 Update Services for SAP Solutions | kernel-0:3.10.0-327.73.1.el7 | Fixed | RHSA-2018:2790 |
| Red Hat Enterprise Linux 7.3 Extended Update Support | kernel-0:3.10.0-514.58.1.el7 | Fixed | RHSA-2018:2785 |
| Red Hat Enterprise Linux 7.4 Extended Update Support | kernel-0:3.10.0-693.39.1.el7 | Fixed | RHSA-2018:2776 |
| Red Hat Enterprise MRG 2 | kernel-rt-1:3.10.0-693.39.1.rt56.629.el6rt | Fixed | RHSA-2018:2789 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 | redhat-release-virtualization-host-0:4.2-5.2.el7 | Fixed | RHSA-2018:2403 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 | redhat-virtualization-host-0:4.2-20180813.0 | Fixed | RHSA-2018:2403 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 | rhvm-appliance-0:4.2-20180813.0 | Fixed | RHSA-2018:2402 |
| Red Hat Enterprise Linux 5 | kernel | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Product Security is aware of this issue. Updates will be released as they become available. For additional information, please refer to the Red Hat Knowledgebase article: https://access.redhat.com/articles/3553061 This issue affects the versions of the Linux kernel as shipped with Red Hat Enterprise Linux 6, 7, its real-time kernel, Red Hat Enterprise MRG 2, Red Hat Enterprise Linux 7 for ARM 64, and Red Hat Enterprise Linux 7 for Power 9. Future kernel updates for the respective releases will address this issue. This issue affects the Linux kernel packages as shipped with Red Hat Enterprise Linux 5, but to a lesser degree. As such, the issue severity for RHEL5 is considered Moderate. This is not currently planned to be addressed in future updates of the product due to its life cycle and the issue severity. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.
References (49)
- http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2018-004.txt x_refsource_CONFIRMThird Party Advisory
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20181031-02-linux-en x_refsource_CONFIRMThird Party Advisory
- http://www.openwall.com/lists/oss-security/2019/06/28/2 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2019/07/06/3 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2019/07/06/4 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- http://www.securityfocus.com/bid/104976 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1041424 vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1041434 vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry
- https://access.redhat.com/articles/3553061
- https://access.redhat.com/errata/RHSA-2018:2384 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2395 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2402 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2403 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2645 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2776 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2785 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2789 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2790 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2791 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2924 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2933 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2948 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2018-5390 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1601704 Issue Tracking
- https://cert-portal.siemens.com/productcert/pdf/ssa-377115.pdf x_refsource_CONFIRMThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2018-17160 Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/davem/net.git/commit/?id=1a4f14bab1868b443f0dd3c55b689a478f82e72e x_refsource_CONFIRMPatchVendor Advisory
- https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0 x_refsource_CONFIRMThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/08/msg00014.html mailing-listx_refsource_MLISTThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-5390
- https://security.netapp.com/advisory/ntap-20180815-0003/ x_refsource_CONFIRMThird Party Advisory
- https://support.f5.com/csp/article/K95343321 x_refsource_CONFIRMThird Party Advisory
- https://support.f5.com/csp/article/K95343321?utm_source=f5support&%3Butm_medium=RSS x_refsource_CONFIRM
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180824-linux-tcp vendor-advisoryx_refsource_CISCOThird Party Advisory
- https://usn.ubuntu.com/3732-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3732-2/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3741-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3741-2/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3742-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3742-2/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3763-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.a10networks.com/support/security-advisories/tcp-ip-cve-2018-5390-segmentsmack x_refsource_CONFIRMMitigationThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2018-5390
- https://www.debian.org/security/2018/dsa-4266 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- https://www.kb.cert.org/vuls/id/962459 third-party-advisoryx_refsource_CERT-VNThird Party AdvisoryUS Government Resource
- https://www.oracle.com/security-alerts/cpujul2020.html x_refsource_MISCThird Party Advisory
- https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html x_refsource_CONFIRMPatchThird Party Advisory
- https://www.spinics.net/lists/netdev/msg514742.html
- https://www.synology.com/support/security/Synology_SA_18_41 x_refsource_CONFIRMThird Party Advisory
Change history (0)
No recorded changes yet.