FlawAtlas
Search the atlas
UBUNTU-CVE-2018-5391 High

UBUNTU-CVE-2018-5391

The Linux kernel, versions 3.9+, is vulnerable to a denial of service attack with low rates of specially modified packets targeting IP fragment re-assembly. An attacker may cause a denial of service condition by sending specially crafted IP fragments. Various vulnerabilities in IP fragmentation have been discovered and fixed over the years. The current vulnerability (CVE-2018-5391) became exploitable in the Linux kernel with the increase of the IP fragment reassembly queue size.

Exploit probability Not scored
Published August 14, 2018
Required by Not available
Last source change April 22, 2026

02 / AFFECTED SOFTWARE

Affected packages

Ubuntu:14.04:LTS linux

134 explicit affected versions

Ubuntu:14.04:LTS linux-aws

16 explicit affected versions

Ubuntu:14.04:LTS linux-lts-xenial

56 explicit affected versions

Ubuntu:16.04:LTS linux

78 explicit affected versions

Ubuntu:16.04:LTS linux-aws

37 explicit affected versions

Ubuntu:16.04:LTS linux-azure

19 explicit affected versions

Ubuntu:16.04:LTS linux-euclid

9 explicit affected versions

Ubuntu:16.04:LTS linux-gcp

17 explicit affected versions

Ubuntu:16.04:LTS linux-hwe

37 explicit affected versions

Ubuntu:16.04:LTS linux-kvm

16 explicit affected versions

Ubuntu:16.04:LTS linux-raspi2

50 explicit affected versions

Ubuntu:16.04:LTS linux-snapdragon

48 explicit affected versions

Ubuntu:18.04:LTS linux

15 explicit affected versions

Ubuntu:18.04:LTS linux-aws

10 explicit affected versions

Ubuntu:18.04:LTS linux-azure

10 explicit affected versions

Ubuntu:18.04:LTS linux-gcp

9 explicit affected versions

Ubuntu:18.04:LTS linux-kvm

10 explicit affected versions

Ubuntu:18.04:LTS linux-oem

7 explicit affected versions

Ubuntu:18.04:LTS linux-raspi2

11 explicit affected versions

Ubuntu:20.04:LTS linux-azure-fde

26 explicit affected versions

Ubuntu:20.04:LTS linux-gke

51 explicit affected versions

Ubuntu:20.04:LTS linux-raspi2

6 explicit affected versions

Ubuntu:20.04:LTS linux-riscv

12 explicit affected versions

Ubuntu:22.04:LTS linux-intel-iot-realtime

1 explicit affected versions

Ubuntu:22.04:LTS linux-realtime

1 explicit affected versions

Ubuntu:22.04:LTS linux-riscv

23 explicit affected versions

Ubuntu:24.04:LTS linux-raspi-realtime

1 explicit affected versions

Ubuntu:Pro:FIPS:16.04:LTS linux-fips

3 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

related USN-3742-2

04 / EVIDENCE

Source records

Open Source Vulnerabilities UBUNTU-CVE-2018-5391

The Linux kernel, versions 3.9+, is vulnerable to a denial of service attack with low rates of specially modified packets targeting IP fragment re-assembly. An attacker may cause a denial of service condition by sending specially crafted IP fragments. Various vulnerabilities in IP fragmentation have been discovered and fixed over the years. The current vulnerability (CVE-2018-5391) became exploitable in the Linux kernel with the increase of the IP fragment reassembly queue size.

View original source

05 / REFERENCES

Further evidence