PT-2015-3358 · Linux+1 · Linux Kernel+1

Farazpajohan

+1

·

Published

2015-06-03

·

Updated

2020-07-31

·

CVE-2017-5972

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions 3.x
Description The TCP stack in the Linux kernel does not properly implement a SYN cookie protection mechanism for the case of a fast network connection, which allows remote attackers to cause a denial of service (CPU consumption) by sending many TCP SYN packets. This issue can be exploited by sending specially crafted SYN packets, leading to CPU consumption.
Recommendations For Linux kernel version 3.x, consider implementing a workaround to limit the impact of SYN packet attacks, such as configuring the system to drop SYN packets after a certain threshold. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2015-1485
ALT-PU-2015-1849
BDU:2018-00380
CVE-2017-5972

Affected Products

Alt Linux
Linux Kernel