Posted on

VU#641765: Linux kernel IP fragment re-assembly vulnerable to denial of service

CWE-400:Uncontrolled Resource Consumption(‘Resource Exhaustion’)- CVE-2018-5391 The Linux kernel,versions 3.9+,is vulnerable to a denial of service attack with low rates of specially modified packets targeting IP fragment re-assembly. An attacker may cause a denial of service condition by sending specially crafted IP fragments. Various vulnerabilities in IP fragmentation have been discovered and fixed over the years. The current vulnerability(CVE-2018-5391)became exploitable in the Linux kernel with the increase of the IP fragment reassembly queue size.

Leave a Reply

Your email address will not be published. Required fields are marked *