Vulnerability record · CVE-2018-5390 · published 6 August 2018
CVE-2018-5390: Linux kernel TCP out-of-order queue processing denial of service
Redhat · Virtualization
Linux kernel versions 4.9 and later can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet. This uncontrolled resource consumption lets a remote sender drive excessive CPU work per packet, degrading or halting TCP service. It matters because the kernel is widely deployed and the flaw is reachable over the network without credentials.
Description
Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can lead to a denial of service.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityCVSS 7.5 with network-reachable, unauthenticated availability impact and very high EPSS, though not in KEV and requiring no user interaction.
What it is
Linux kernel versions 4.9 and later can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet. This uncontrolled resource consumption lets a remote sender drive excessive CPU work per packet, degrading or halting TCP service. It matters because the kernel is widely deployed and the flaw is reachable over the network without credentials.
Impact
An attacker can exhaust CPU resources on the target, causing a denial of service for TCP traffic handled by the affected kernel. No confidentiality or integrity impact is described; the effect is availability loss.
Attack surface
Reached over the network via TCP packets, per the CVSS vector AV:N/AC:L/PR:N/UI:N. No authentication or user interaction is required; any host exposing a TCP service on an affected kernel is a candidate.
Exploitation
Not listed in CISA KEV, but EPSS is high at 0.7372 (99.45th percentile), indicating elevated likelihood of exploitation activity. Reference tags are advisory, patch, and mailing list entries; no public exploit code is cited in the record.
What to do
- Apply the vendor kernel updates referenced in the Red Hat, Debian, Ubuntu, and upstream kernel patch advisories.
- Prioritize patching internet-facing and high-throughput TCP endpoints, including load balancers and ADC appliances from the listed vendors.
- Where patching is delayed, rate-limit or filter abusive TCP traffic at the network edge and monitor for sustained per-packet CPU spikes.
- Track vendor advisories for the listed products (Red Hat, Canonical, Debian, HP, F5, A10 Networks, Cisco, Aruba) to confirm coverage.
Detection
- Monitor kernel CPU utilization and softirq/network processing time for sustained spikes correlated with inbound TCP traffic.
- Alert on sudden drops in TCP throughput or connection resets on hosts running unpatched kernels.
- Baseline per-packet processing cost on exposed TCP services and flag deviations consistent with expensive out-of-order queue handling.
- Review edge and load balancer logs for high-rate or anomalous TCP connection patterns targeting affected hosts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
38 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2018-5390 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-5390), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.