A security flaw was found in the ip_frag_reasm() function in net/ipv4/ip_fragment.c in the Linux kernel from 4.19-rc1 to 4.19-rc3 inclusive, which can cause a later system crash in ip_do_fragment(). With certain non-default, but non-rare, configuration of a victim host, an attacker can trigger this crash remotely, thus leading to a remote denial-of-service.
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.0 Base Score: 6.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade kernel | Aug 28, 2019 | Sep 18, 2018 |
| Huawei Euleros 2_0_sp5 | — | Upgrade kernel-toolsUpgrade python-perfUpgrade kernel-tools-libsUpgrade perfUpgrade kernel-debuginfo-common-x86_64Upgrade kernelUpgrade kernel-debuginfoUpgrade kernel-develUpgrade kernel-headers | Mar 11, 2019 | Sep 18, 2018 |
| Redhat_linux | — | Upgrade kernel | Oct 31, 2018 | Sep 18, 2018 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Sep 18, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub