The Linux kernel, versions 3.9+, IP implementation is vulnerable to denial of service conditions with low rates of specially modified packets
Published Sep 6, 2018
7.5
HIGHCVSS 3.1
EPSS 32.45%
Description
The Linux kernel, versions 3.9+, is vulnerable to a denial of service attack with low rates of specially modified packets targeting IP fragment re-assembly. An attacker may cause a denial of service condition by sending specially crafted IP fragments. Various vulnerabilities in IP fragmentation have been discovered and fixed over the years. The current vulnerability (CVE-2018-5391) became exploitable in the Linux kernel with the increase of the IP fragment reassembly queue size.
Affected products
-
- Version 3.9StatusaffectedConstraints<3.9*
- Version
Configuration 1
- ≥ 3.9 · ≤ 4.18
Configuration 2
- 6.0
- 7.0
- 6.0
- 7.0
- 6.4
- 6.5
- 6.6
- 7.2
- 7.3
- 7.4
- 6.7
- 7.3
- 7.4
- 7.5
- 6.6
- 7.2
- 7.3
- 7.4
- 6.0
- 7.0
Configuration 3
- 8.0
- 9.0
Configuration 4
- 12.04
- 14.04
- 16.04
- 18.04
Configuration 5
- n/a
- 1607
- 1703
- 1709
- 1803
- n/a
- n/a
- n/a
- n/a
- r2
- r2
- n/a
- r2
- n/a
- 1709
- 1803
Configuration 6
- ≥ 11.5.1 · < 11.6.5.1
- ≥ 12.1.0 · < 12.1.5
- ≥ 13.0.0 · < 13.1.3
- ≥ 14.0.0 · < 14.0.1.1
- ≥ 14.1.0 · < 14.1.2.4
- ≥ 11.5.1 · < 11.6.5.1
- ≥ 12.1.0 · < 12.1.5
- ≥ 13.0.0 · < 13.1.3
- ≥ 14.0.0 · < 14.0.1.1
- ≥ 14.1.0 · < 14.1.2.4
- ≥ 11.5.1 · < 11.6.5.1
- ≥ 12.1.0 · < 12.1.5
- ≥ 13.0.0 · < 13.1.3
- ≥ 14.0.0 · < 14.0.1.1
- ≥ 14.1.0 · < 14.1.2.4
- ≥ 11.5.1 · < 11.6.5.1
- ≥ 12.1.0 · < 12.1.5
- ≥ 13.0.0 · < 13.1.3
- ≥ 14.0.0 · < 14.0.1.1
- ≥ 14.1.0 · < 14.1.2.4
- ≥ 11.5.1 · < 11.6.5.1
- ≥ 12.1.0 · < 12.1.5
- ≥ 13.0.0 · < 13.1.3
- ≥ 14.0.0 · < 14.0.1.1
- ≥ 14.1.0 · < 14.1.2.4
- ≥ 11.5.1 · < 11.6.5.1
- ≥ 12.1.0 · < 12.1.5
- ≥ 13.0.0 · < 13.1.3
- ≥ 14.0.0 · < 14.0.1.1
- ≥ 14.1.0 · < 14.1.2.4
- ≥ 11.5.1 · < 11.6.5.1
- ≥ 12.1.0 · < 12.1.5
- ≥ 13.0.0 · < 13.1.3
- ≥ 14.0.0 · < 14.0.1.1
- ≥ 14.1.0 · < 14.1.2.4
- ≥ 11.5.1 · < 11.6.5.1
- ≥ 12.1.0 · < 12.1.5
- ≥ 13.0.0 · < 13.1.3
- ≥ 14.0.0 · < 14.0.1.1
- ≥ 14.1.0 · < 14.1.2.4
- ≥ 11.5.1 · < 11.6.5.1
- ≥ 12.1.0 · < 12.1.5
- ≥ 13.0.0 · < 13.1.3
- ≥ 14.0.0 · < 14.0.1.1
- ≥ 14.1.0 · < 14.1.2.4
- ≥ 11.5.1 · < 11.6.5.1
- ≥ 12.1.0 · < 12.1.5
- ≥ 13.0.0 · < 13.1.3
- ≥ 14.0.0 · < 14.0.1.1
- ≥ 14.1.0 · < 14.1.2.4
- ≥ 11.5.1 · < 11.6.5.1
- ≥ 12.1.0 · < 12.1.5
- ≥ 13.0.0 · < 13.1.3
- ≥ 14.0.0 · < 14.0.1.1
- ≥ 14.1.0 · < 14.1.2.4
- ≥ 11.5.1 · < 11.6.5.1
- ≥ 12.1.0 · < 12.1.5
- ≥ 13.0.0 · < 13.1.3
- ≥ 14.0.0 · < 14.0.1.1
- ≥ 14.1.0 · < 14.1.2.4
- ≥ 11.5.1 · < 11.6.5.1
- ≥ 12.1.0 · < 12.1.5
- ≥ 13.0.0 · < 13.1.3
- ≥ 14.0.0 · < 14.0.1.1
- ≥ 14.1.0 · < 14.1.2.4
Configuration 7
- < 6.1
Running on/with
- n/a
Configuration 8
- < 2.13.3
Running on/with
- n/a
Configuration 9
- < 6.1
Running on/with
- n/a
Configuration 10
- < 6.1
Running on/with
- n/a
Configuration 11
- < 2.0
Running on/with
- n/a
Configuration 12
- < 2.0
Running on/with
- n/a
Configuration 13
Running on/with
- n/a
Configuration 14
- < 3.2
Running on/with
- n/a
Configuration 15
- < 3.2
Running on/with
- n/a
Configuration 16
- < 3.2
Running on/with
- n/a
Configuration 17
- < 3.2
Running on/with
- n/a
Configuration 18
- < 3.2
Running on/with
- n/a
Configuration 19
- < 2.1
Running on/with
- n/a
Configuration 20
- < 2.1
Running on/with
- n/a
Configuration 21
- < 2.2
Running on/with
- n/a
Configuration 22
- < 2.1
Running on/with
- n/a
Configuration 23
- < 1.3
Running on/with
- n/a
Configuration 24
- < 1.3
Running on/with
- n/a
Configuration 25
- < 1.3
Running on/with
- n/a
Configuration 26
- < 1.3
Running on/with
- n/a
Configuration 27
- < 1.3
Running on/with
- n/a
Configuration 28
- ≥ 1.1 · < 2.0.1
Running on/with
- n/a
No data.
Red Hat Enterprise Linux 6
kernel-0:2.6.32-754.6.3.el6
Fixed · RHSA-2018:2846
Red Hat Enterprise Linux 6.4 Advanced Update Support
kernel-0:2.6.32-358.93.1.el6
Fixed · RHSA-2018:2791
Red Hat Enterprise Linux 6.5 Advanced Update Support
kernel-0:2.6.32-431.93.2.el6
Fixed · RHSA-2018:2933
Red Hat Enterprise Linux 6.6 Advanced Update Support
kernel-0:2.6.32-504.76.2.el6
Fixed · RHSA-2018:2924
Red Hat Enterprise Linux 6.6 Telco Extended Update Support
kernel-0:2.6.32-504.76.2.el6
Fixed · RHSA-2018:2924
Red Hat Enterprise Linux 6.7 Extended Update Support
kernel-0:2.6.32-573.65.2.el6
Fixed · RHSA-2018:2925
Red Hat Enterprise Linux 7
kernel-0:3.10.0-957.el7
Fixed · RHSA-2018:3083
Red Hat Enterprise Linux 7
kernel-alt-0:4.14.0-115.el7a
Fixed · RHSA-2018:2948
Red Hat Enterprise Linux 7
kernel-rt-0:3.10.0-957.rt56.910.el7
Fixed · RHSA-2018:3096
Red Hat Enterprise Linux 7.2 Advanced Update Support
kernel-0:3.10.0-327.76.1.el7
Fixed · RHSA-2018:3590
Red Hat Enterprise Linux 7.2 Telco Extended Update Support
kernel-0:3.10.0-327.76.1.el7
Fixed · RHSA-2018:3590
Red Hat Enterprise Linux 7.2 Update Services for SAP Solutions
kernel-0:3.10.0-327.76.1.el7
Fixed · RHSA-2018:3590
Red Hat Enterprise Linux 7.3 Extended Update Support
kernel-0:3.10.0-514.58.1.el7
Fixed · RHSA-2018:2785
Red Hat Enterprise Linux 7.4 Extended Update Support
kernel-0:3.10.0-693.43.1.el7
Fixed · RHSA-2018:3540
Red Hat Enterprise Linux 7.5 Extended Update Support
kernel-0:3.10.0-862.20.2.el7
Fixed · RHSA-2018:3459
Red Hat Enterprise MRG 2
kernel-rt-1:3.10.0-693.43.1.rt56.630.el6rt
Fixed · RHSA-2018:3586
Red Hat Enterprise Linux 5
kernel
Will not fix
Red Hat Enterprise Linux 8
kernel
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel-0:2.6.32-754.6.3.el6 | Fixed | RHSA-2018:2846 |
| Red Hat Enterprise Linux 6.4 Advanced Update Support | kernel-0:2.6.32-358.93.1.el6 | Fixed | RHSA-2018:2791 |
| Red Hat Enterprise Linux 6.5 Advanced Update Support | kernel-0:2.6.32-431.93.2.el6 | Fixed | RHSA-2018:2933 |
| Red Hat Enterprise Linux 6.6 Advanced Update Support | kernel-0:2.6.32-504.76.2.el6 | Fixed | RHSA-2018:2924 |
| Red Hat Enterprise Linux 6.6 Telco Extended Update Support | kernel-0:2.6.32-504.76.2.el6 | Fixed | RHSA-2018:2924 |
| Red Hat Enterprise Linux 6.7 Extended Update Support | kernel-0:2.6.32-573.65.2.el6 | Fixed | RHSA-2018:2925 |
| Red Hat Enterprise Linux 7 | kernel-0:3.10.0-957.el7 | Fixed | RHSA-2018:3083 |
| Red Hat Enterprise Linux 7 | kernel-alt-0:4.14.0-115.el7a | Fixed | RHSA-2018:2948 |
| Red Hat Enterprise Linux 7 | kernel-rt-0:3.10.0-957.rt56.910.el7 | Fixed | RHSA-2018:3096 |
| Red Hat Enterprise Linux 7.2 Advanced Update Support | kernel-0:3.10.0-327.76.1.el7 | Fixed | RHSA-2018:3590 |
| Red Hat Enterprise Linux 7.2 Telco Extended Update Support | kernel-0:3.10.0-327.76.1.el7 | Fixed | RHSA-2018:3590 |
| Red Hat Enterprise Linux 7.2 Update Services for SAP Solutions | kernel-0:3.10.0-327.76.1.el7 | Fixed | RHSA-2018:3590 |
| Red Hat Enterprise Linux 7.3 Extended Update Support | kernel-0:3.10.0-514.58.1.el7 | Fixed | RHSA-2018:2785 |
| Red Hat Enterprise Linux 7.4 Extended Update Support | kernel-0:3.10.0-693.43.1.el7 | Fixed | RHSA-2018:3540 |
| Red Hat Enterprise Linux 7.5 Extended Update Support | kernel-0:3.10.0-862.20.2.el7 | Fixed | RHSA-2018:3459 |
| Red Hat Enterprise MRG 2 | kernel-rt-1:3.10.0-693.43.1.rt56.630.el6rt | Fixed | RHSA-2018:3586 |
| Red Hat Enterprise Linux 5 | kernel | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Product Security is aware of this issue. Updates will be released as they become available. For additional information, please refer to the Red Hat Knowledgebase article: https://access.redhat.com/articles/3553061 This issue affects the versions of the Linux kernel as shipped with Red Hat Enterprise Linux 6, 7, its real-time kernel, Red Hat Enterprise MRG 2, Red Hat Enterprise Linux 7 for ARM 64, and Red Hat Enterprise Linux 7 for Power 9. Future kernel updates for the respective releases will address this issue. This issue affects the Linux kernel packages as shipped with Red Hat Enterprise Linux 5, but to a lesser degree. As such, the issue severity for RHEL5 is considered Moderate. This is not currently planned to be addressed in future updates of the product due to its life cycle and the issue severity. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.
Red Hat mitigation
One may change the default 4MB and 3MB values of net.ipv4.ipfrag_high_thresh and net.ipv4.ipfrag_low_thresh (and their ipv6 counterparts net.ipv6.ipfrag_high_thresh and net.ipv6.ipfrag_low_thresh) to 256 kB and 192 kB (respectively) or below. Tests show some to significant CPU saturation drop during an attack, depending on a hardware, configuration and environment. There can be some impact on performance though, due to ipfrag_high_thresh of 262144 bytes, as only two 64K fragments can fit in the reassembly queue at the same time. For example, there is a risk of breaking applications that rely on large UDP packets. See the Mitigation section in the https://access.redhat.com/articles/3553061 article for the script to quickly change to/from default and lower settings.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
AV:N/AC:L/Au:N/C:N/I:N/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (38 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 32.45% (0.32445) | 98.29th | v5 (v2026.06.15) |
| Aug 2, 2026 | 32.45% (0.32445) | 98.16th | v5 (v2026.06.15) |
| Jun 15, 2026 | 24.15% (0.24149) | 97.56th | v5 (v2026.06.15) |
| Feb 18, 2026 | 3.82% (0.03822) | 87.87th | v4 (v2025.03.14) |
| Dec 29, 2025 | 5.10% (0.05102) | 89.48th | v4 (v2025.03.14) |
| Dec 28, 2025 | 3.82% (0.03822) | 87.77th | v4 (v2025.03.14) |
| Dec 27, 2025 | 5.02% (0.05017) | 89.42th | v4 (v2025.03.14) |
| Nov 21, 2025 | 3.82% (0.03822) | 87.66th | v4 (v2025.03.14) |
| Nov 18, 2025 | 15.20% (0.15200) | 94.00th | v4 (v2025.03.14) |
| Oct 28, 2025 | 3.82% (0.03822) | 87.62th | v4 (v2025.03.14) |
| Oct 27, 2025 | 5.02% (0.05017) | 89.25th | v4 (v2025.03.14) |
| Oct 1, 2025 | 3.82% (0.03822) | 87.71th | v4 (v2025.03.14) |
| Aug 31, 2025 | 5.02% (0.05017) | 89.31th | v4 (v2025.03.14) |
| Aug 30, 2025 | 2.80% (0.02802) | 85.56th | v4 (v2025.03.14) |
| Mar 30, 2025 | 1.71% (0.01712) | 80.66th | v4 (v2025.03.14) |
| Mar 29, 2025 | 21.22% (0.21220) | 92.94th | v4 (v2025.03.14) |
| Mar 17, 2025 | 1.71% (0.01712) | 81.10th | v4 (v2025.03.14) |
| Dec 17, 2024 | 10.33% (0.10331) | 94.96th | v3 (v2023.03.01) |
| Dec 12, 2024 | 1.67% (0.01674) | 88.17th | v3 (v2023.03.01) |
| Jun 21, 2024 | 1.66% (0.01656) | 87.68th | v3 (v2023.03.01) |
| Apr 25, 2024 | 1.56% (0.01560) | 87.03th | v3 (v2023.03.01) |
| Mar 8, 2024 | 1.85% (0.01851) | 88.00th | v3 (v2023.03.01) |
| Feb 18, 2024 | 1.62% (0.01623) | 87.10th | v3 (v2023.03.01) |
| Jan 28, 2024 | 1.15% (0.01150) | 83.30th | v3 (v2023.03.01) |
| Dec 16, 2023 | 1.64% (0.01637) | 86.15th | v3 (v2023.03.01) |
| Aug 31, 2023 | 1.16% (0.01160) | 83.11th | v3 (v2023.03.01) |
| Jul 8, 2023 | 0.99% (0.00987) | 81.42th | v3 (v2023.03.01) |
| May 8, 2023 | 1.26% (0.01255) | 83.49th | v3 (v2023.03.01) |
| May 4, 2023 | 0.99% (0.00987) | 81.29th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.98% (0.00979) | 81.10th | v3 (v2023.03.01) |
| Mar 6, 2023 | 32.43% (0.32427) | 97.60th | v2 (v2022.01.01) |
| Dec 29, 2022 | 32.43% (0.32427) | 97.57th | v2 (v2022.01.01) |
| Apr 1, 2022 | 2.69% (0.02686) | 81.17th | v2 (v2022.01.01) |
| Feb 4, 2022 | 2.69% (0.02686) | 62.66th | v2 (v2022.01.01) |
| Feb 3, 2022 | 8.73% (0.08735) | 85.98th | v1 |
| Jan 6, 2022 | 8.73% (0.08735) | 85.81th | v1 |
| Sep 1, 2021 | 8.73% (0.08735) | 93.15th | v1 |
| Apr 14, 2021 | 8.73% (0.08735) | 0.00th | v1 |
References (40)
- http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2018-004.txt x_refsource_CONFIRMThird Party Advisory
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200115-01-linux-en x_refsource_CONFIRMBroken Link
- http://www.openwall.com/lists/oss-security/2019/06/28/2 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2019/07/06/3 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2019/07/06/4 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- http://www.securityfocus.com/bid/105108 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1041476 vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1041637 vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry
- https://access.redhat.com/articles/3553061
- https://access.redhat.com/errata/RHSA-2018:2785 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2791 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2846 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2924 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2925 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2933 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2948 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3083 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3096 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3459 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3540 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3586 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3590 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2018-5391 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1609664 Issue Tracking
- https://cert-portal.siemens.com/productcert/pdf/ssa-377115.pdf x_refsource_CONFIRMThird Party Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/davem/net-next.git/commit/?id=c30f1fc041b74ecdb072dd44f858750414b8b19f x_refsource_MISCPatchVendor Advisory
- https://lists.debian.org/debian-lts-announce/2018/08/msg00014.html mailing-listx_refsource_MLISTMailing ListMitigationThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/03/msg00017.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-5391
- https://security.netapp.com/advisory/ntap-20181003-0002/ x_refsource_CONFIRMThird Party Advisory
- https://support.f5.com/csp/article/K74374841?utm_source=f5support&%3Butm_medium=RSS x_refsource_CONFIRM
- https://usn.ubuntu.com/3740-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3740-2/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3741-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3741-2/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3742-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3742-2/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2018-5391
- https://www.debian.org/security/2018/dsa-4272 vendor-advisoryx_refsource_DEBIANMitigationThird Party Advisory
- https://www.kb.cert.org/vuls/id/641765 third-party-advisoryx_refsource_CERT-VNThird Party AdvisoryUS Government Resource
Change history (0)
No recorded changes yet.