Lucene search

K
cve[email protected]CVE-2018-6922
HistoryAug 09, 2018 - 6:29 p.m.

CVE-2018-6922

2018-08-0918:29:00
CWE-400
web.nvd.nist.gov
107
cve-2018-6922
freebsd
tcp
network performance
cpu consumption
security vulnerability

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

5.2 Medium

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

74.9%

One of the data structures that holds TCP segments in all versions of FreeBSD prior to 11.2-RELEASE-p1, 11.1-RELEASE-p12, and 10.4-RELEASE-p10 uses an inefficient algorithm to reassemble the data. This causes the CPU time spent on segment processing to grow linearly with the number of segments in the reassembly queue. An attacker who has the ability to send TCP traffic to a victim system can degrade the victim system’s network performance and/or consume excessive CPU by exploiting the inefficiency of TCP reassembly handling, with relatively small bandwidth cost.

Affected configurations

NVD
Node
freebsdfreebsdMatch10.4-
OR
freebsdfreebsdMatch10.4p1
OR
freebsdfreebsdMatch10.4p3
OR
freebsdfreebsdMatch10.4p4
OR
freebsdfreebsdMatch10.4p5
OR
freebsdfreebsdMatch10.4p6
OR
freebsdfreebsdMatch10.4p7
OR
freebsdfreebsdMatch10.4p8
OR
freebsdfreebsdMatch10.4p9
OR
freebsdfreebsdMatch11.1-
OR
freebsdfreebsdMatch11.1p1
OR
freebsdfreebsdMatch11.1p11
OR
freebsdfreebsdMatch11.1p2
OR
freebsdfreebsdMatch11.1p4
OR
freebsdfreebsdMatch11.1p5
OR
freebsdfreebsdMatch11.1p6
OR
freebsdfreebsdMatch11.1p7
OR
freebsdfreebsdMatch11.1p9
OR
freebsdfreebsdMatch11.2-

CNA Affected

[
  {
    "product": "FreeBSD",
    "vendor": "FreeBSD",
    "versions": [
      {
        "status": "affected",
        "version": "All versions prior to 11.2-RELEASE-p1, 11.1-RELEASE-p12, 10.4-RELEASE-p10"
      }
    ]
  }
]

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

5.2 Medium

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

74.9%