CVE-2018-5390, also known as "SegmentSmack," is a denial-of-service vulnerability affecting Linux kernel versions 4.9 and later, impacting various products from vendors like Canonical, Red Hat, and Cisco. An unauthenticated remote attacker can exploit this flaw by forcing the kernel to execute resource-intensive TCP queue operations for every incoming packet. With a CVSS score of 7.5 (High), this vulnerability is easily exploitable over the network with low attack complexity, leading to a complete denial of service. While not listed in CISA's KEV catalog and lacking public exploit code in Metasploit or ExploitDB, it has garnered significant community discussion and media coverage, indicating awareness and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.0CPE matchmatch criteria | cpe:2.3:a:redhat:virtualization:4.0:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:* | ||
6.4CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_server_aus:6.4:*:*:*:*:*:*:* | ||
6.5CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_server_aus:6.5:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.