Linux Kernel TCP Segment Out of Order Denial of Service

Strike ID:
D18-0n5a1
CVSS:
7.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
False Positive:
f
Variants:
1
Year:
2018

Description

This strike exploits a denial of service vulnerability in Linux Kernel TCP segments. The vulnerability is caused by the way how out-of-order TCP segments are stored and handled from the function tcp_collapse_ofo_queue() and tcp_prune_ofo_queue(). A remote attacker could exploit this vulnerability by keep sending crafted TCP segments packet to the target server. Successful exploitation is able to exhaust target server's resource and lead to denial-of-service.

CVE

References

Bid