5.3

CVE-2018-6922

One of the data structures that holds TCP segments in all versions of FreeBSD prior to 11.2-RELEASE-p1, 11.1-RELEASE-p12, and 10.4-RELEASE-p10 uses an inefficient algorithm to reassemble the data. This causes the CPU time spent on segment processing to grow linearly with the number of segments in the reassembly queue. An attacker who has the ability to send TCP traffic to a victim system can degrade the victim system's network performance and/or consume excessive CPU by exploiting the inefficiency of TCP reassembly handling, with relatively small bandwidth cost.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Freebsd ≫ Freebsd Version 10.4 Update -
Freebsd ≫ Freebsd Version 10.4 Update p1
Freebsd ≫ Freebsd Version 10.4 Update p3
Freebsd ≫ Freebsd Version 10.4 Update p4
Freebsd ≫ Freebsd Version 10.4 Update p5
Freebsd ≫ Freebsd Version 10.4 Update p6
Freebsd ≫ Freebsd Version 10.4 Update p7
Freebsd ≫ Freebsd Version 10.4 Update p8
Freebsd ≫ Freebsd Version 10.4 Update p9
Freebsd ≫ Freebsd Version 11.1 Update -
Freebsd ≫ Freebsd Version 11.1 Update p1
Freebsd ≫ Freebsd Version 11.1 Update p11
Freebsd ≫ Freebsd Version 11.1 Update p2
Freebsd ≫ Freebsd Version 11.1 Update p4
Freebsd ≫ Freebsd Version 11.1 Update p5
Freebsd ≫ Freebsd Version 11.1 Update p6
Freebsd ≫ Freebsd Version 11.1 Update p7
Freebsd ≫ Freebsd Version 11.1 Update p9
Freebsd ≫ Freebsd Version 11.2 Update -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.23% 0.866
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.3 3.9 1.4
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-400 Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource.

https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html
Patch
http://www.securityfocus.com/bid/105058
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1041425
Third Party Advisory
VDB Entry
https://security.netapp.com/advisory/ntap-20180815-0002/
Third Party Advisory
https://www.freebsd.org/security/advisories/FreeBSD-SA-18:08.tcp.asc
Patch
Vendor Advisory