Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-6922

Опубликовано: 09 авг. 2018
Источник: nvd
CVSS3: 5.3
CVSS2: 5
EPSS Низкий

Описание

One of the data structures that holds TCP segments in all versions of FreeBSD prior to 11.2-RELEASE-p1, 11.1-RELEASE-p12, and 10.4-RELEASE-p10 uses an inefficient algorithm to reassemble the data. This causes the CPU time spent on segment processing to grow linearly with the number of segments in the reassembly queue. An attacker who has the ability to send TCP traffic to a victim system can degrade the victim system's network performance and/or consume excessive CPU by exploiting the inefficiency of TCP reassembly handling, with relatively small bandwidth cost.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:o:freebsd:freebsd:10.4:-:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:10.4:p1:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:10.4:p3:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:10.4:p4:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:10.4:p5:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:10.4:p6:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:10.4:p7:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:10.4:p8:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:10.4:p9:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:11.1:-:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:11.1:p1:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:11.1:p11:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:11.1:p2:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:11.1:p4:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:11.1:p5:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:11.1:p6:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:11.1:p7:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:11.1:p9:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:11.2:-:*:*:*:*:*:*

EPSS

Процентиль: 71%
0.00697
Низкий

5.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-400
CWE-400

Связанные уязвимости

CVSS3: 5.3
debian
больше 7 лет назад

One of the data structures that holds TCP segments in all versions of ...

CVSS3: 5.3
github
больше 3 лет назад

One of the data structures that holds TCP segments in all versions of FreeBSD prior to 11.2-RELEASE-p1, 11.1-RELEASE-p12, and 10.4-RELEASE-p10 uses an inefficient algorithm to reassemble the data. This causes the CPU time spent on segment processing to grow linearly with the number of segments in the reassembly queue. An attacker who has the ability to send TCP traffic to a victim system can degrade the victim system's network performance and/or consume excessive CPU by exploiting the inefficiency of TCP reassembly handling, with relatively small bandwidth cost.

CVSS3: 7.5
fstec
больше 7 лет назад

Уязвимость ядра операционных систем Linux и FreeBSD, связанная с ошибками алгоритмов пересборки пакетов в стеках TCP, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 71%
0.00697
Низкий

5.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-400
CWE-400