Lucene search

K
ibmIBM5D040B14C9E224DB74795E7F7CBD38606A7A1D5E621389973BBE66DC347EDD86
HistoryDec 07, 2021 - 7:14 p.m.

Security Bulletin: This Power System update is being released to address CVE-2018-5390

2021-12-0719:14:45
www.ibm.com
26
power system
update
fix
cve-2018-5390
denial of service
firmware
ibm
power systems s922
power systems h922
power systems s914
power systems s924
power systems h924
power systems l922
power systems e950
power systems e980

EPSS

0.783

Percentile

98.3%

Summary

POWER9: In response to a denial of service vulnerability, a new Power Systems firmware update is being released to address Common Vulnerabilities and Exposures issue number CVE-2018-5390.

Vulnerability Details

CVEID: CVE-2018-5390 DESCRIPTION: Linux Kernel is vulnerable to a denial of service, caused by an error in the tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() functions. By sending specially crafted packets within ongoing TCP sessions, a remote attacker could exploit this vulnerability to cause a denial of service.
CVSS Base Score: 7.5
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/147950&gt; for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Affected Products and Versions

Firmware release FW910 and FW920 are affected.

Remediation/Fixes

Customers with the products below, install FW910.30

  1. IBM Power Systems S922 (9009-22A)
  2. IBM Power Systems H922 (9223-22H)
  3. IBM Power Systems S914 (9009-41A)
  4. IBM Power Systems S924 (9009-42A)
  5. IBM Power Systems H924 (9223-42H)
  6. IBM Power Systems L922 (9008-22L)

Customers with the products below, install FW920.30

  1. IBM Power Systems E950(9040-MR9)

  2. IBM Power Systems E980(9080-M9S)