PT-2018-1834 · Arista Networks+9 · Arista Eos+12

Juha-Matti Tilli

·

Published

2018-06-09

·

Updated

2022-12-28

·

CVE-2018-5391

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions: Linux kernel versions 3.9 and later PAN-OS versions prior to 6.1.22 PAN-OS versions prior to 7.1.20 PAN-OS versions prior to 8.0.13 PAN-OS versions prior to 8.1.5 Arista EOS (affected versions not specified) vEOS (affected versions not specified) CloudVision Portal (affected versions not specified) CloudVision Appliance (affected versions not specified) Check Point GAiA (affected versions not specified)
Description: The issue is related to a denial of service attack that can be triggered by sending specially crafted IP fragments, causing CPU saturation and consuming excessive resources. This can lead to a denial of service condition. The vulnerability is known as a FragmentSmack attack and affects the Linux kernel's handling of IP fragment reassembly. Remote attackers can exploit this issue by sending fragmented IPv4 or IPv6 packets to the affected device.
Recommendations: For Linux kernel versions 3.9 and later, consider disabling IP fragment reassembly or restricting the size of the IP fragment reassembly queue as a temporary workaround until a patch is available. For PAN-OS versions prior to 6.1.22, update to version 6.1.22 or later. For PAN-OS versions prior to 7.1.20, update to version 7.1.20 or later. For PAN-OS versions prior to 8.0.13, update to version 8.0.13 or later. For PAN-OS versions prior to 8.1.5, update to version 8.1.5 or later. For Arista EOS, vEOS, CloudVision Portal, and CloudVision Appliance, refer to the vendor's documentation for affected versions, mitigation, and resolution. For Check Point GAiA, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Resource Exhaustion

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2192
ALT-PU-2018-2210
ALT-PU-2019-1433
BDU:2018-01436
CESA-2018_2846
CESA-2018_3083
CVE-2018-5391
DLA-1466-1
DLA-1529-1
DLA-1715-1
DSA-4272-1
MGASA-2018-0391
MGASA-2018-0418
MGASA-2018-0419
OPENSUSE-SU-2018_2404-1
OPENSUSE-SU-2018_2407-1
OPENSUSE-SU-2019_0274-1
RHSA-2018:2785
RHSA-2018:2791
RHSA-2018:2846
RHSA-2018:2924
RHSA-2018:2925
RHSA-2018:2933
RHSA-2018:2948
RHSA-2018:3083
RHSA-2018:3096
RHSA-2018:3459
RHSA-2018:3540
RHSA-2018:3586
RHSA-2018:3590
RHSA-2018_2846
RHSA-2018_3083
RHSA-2018_3096
SUSE-SU-2018:2344-1
SUSE-SU-2018:2344-2
SUSE-SU-2018:2374-1
SUSE-SU-2018:2380-1
SUSE-SU-2018:2381-1
SUSE-SU-2018:2450-1
SUSE-SU-2018:2596-1
SUSE-SU-2018:3787-1
SUSE-SU-2018:3792-1
SUSE-SU-2018:3860-1
SUSE-SU-2018:3865-1
SUSE-SU-2018:3880-1
SUSE-SU-2018:3881-1
SUSE-SU-2018_3792-1
SUSE-SU-2018_3881-1
SUSE-SU-2019:0541-1
SUSE-SU-2019:0645-1
SUSE-SU-2019:0672-1
SUSE-SU-2019:1289-1
SUSE-SU-2019_0645-1
SUSE-SU-2019_0672-1
USN-3740-1
USN-3740-2
USN-3741-1
USN-3741-2
USN-3741-3
USN-3742-1
USN-3742-2

Affected Products

Alt Linux
Arista Eos
Centos
Check Point Gaia
Cloudvision Appliance
Cloudvision Portal
Huawei Vrp
Linux Kernel
Pan-Os
Red Hat
Suse
Ubuntu
Veos