VOMIT (go/vomit) has received an external vulnerability report for the Linux kernel.
Advisory: CVE-2018-5390
Details: http://vomit.googleplex.com/advisory?id=CVE/CVE-2018-5390
CVSS severity score: 7.8/10.0
Description:
Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can lead to a denial of service.
This bug was filed by http://go/vomit
Please contact us at vomit-team@google.com if you need any assistance.
Comment 1 by groeck@chromium.org
, Oct 12Mergedinto: 866800
Status: Duplicate (was: Untriaged)