CVE-2017-5972 describes a denial-of-service vulnerability in the TCP stack of Linux kernel 3.x, specifically affecting fast network connections. This flaw, demonstrated against CentOS Linux 7, stems from an improper SYN cookie protection mechanism, allowing remote attackers to consume CPU resources by flooding the system with TCP SYN packets. The vulnerability is rated as High severity (CVSS 7.5), requiring no authentication or user interaction, and leading to high availability impact. While not listed on the KEV catalog or showing active exploitation, public exploit code exists (EDB-41350), though there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.0.0, <= 3.19.8CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.