<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T17:07:42.524000+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2018-01436</id>
    <title>bdu:2018-01436</title>
    <updated>2026-10-02T17:07:42.584132+00:00</updated>
    <content>bdu:2018-01436</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2018-01436"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2018-5391</id>
    <title>Withdrawn: BELL-CVE-2018-5391 — CVE-2018-5391 does not affect BellSoft software</title>
    <updated>2026-10-02T17:07:42.584184+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2018-5391"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2018-avi-390</id>
    <title>certfr-2018-avi-390 — De multiples vulnérabilités ont été découvertes dans le noyau Linux
d'Ubuntu. Elles permettent à un attaquant de provoq…</title>
    <updated>2026-10-02T17:07:42.584205+00:00</updated>
    <content>certfr-2018-avi-390</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2018-avi-390"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cisco-sa-20180824-linux-ip-fragment</id>
    <title>cisco-sa-20180824-linux-ip-fragment — Linux Kernel IP Fragment Reassembly Denial of Service Vulnerability Affecting Cisco Products: August 2018</title>
    <updated>2026-10-02T17:07:42.584221+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>On August 14, 2018, the Vulnerability Coordination team of the National Cyber Security Centre of Finland (NCSC-FI) and the CERT Coordination Center (CERT/CC) disclosed a vulnerability in the IP stack that is used by the Linux Kernel. This vulnerability is publicly known as FragmentSmack.

The vulnerability could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. An attack could be executed by an attacker who can submit a stream of fragmented IPv4 or IPv6 packets that are designed to trigger the issue on an affected device.

The vulnerability is due to inefficient IPv4 and IPv6 fragment reassembly algorithms in the IP stack that is used by the affected kernel. Linux Kernel Versions 3.9 and later are known to be affected by this vulnerability.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180824-linux-ip-fragment ["https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180824-linux-ip-fragment"]</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cisco-sa-20180824-linux-ip-fragment"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2018-24552</id>
    <title>cnvd-2018-24552</title>
    <updated>2026-10-02T17:07:42.584328+00:00</updated>
    <content>cnvd-2018-24552</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2018-24552"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-62231</id>
    <title>EUVD-2026-62231</title>
    <updated>2026-10-02T17:07:42.584345+00:00</updated>
    <content>EUVD-2026-62231</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-62231"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2018-5391</id>
    <title>fkie_cve-2018-5391</title>
    <updated>2026-10-02T17:07:42.584357+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The Linux kernel, versions 3.9+, is vulnerable to a denial of service attack with low rates of specially modified packets targeting IP fragment re-assembly. An attacker may cause a denial of service condition by sending specially crafted IP fragments. Various vulnerabilities in IP fragmentation have been discovered and fixed over the years. The current vulnerability (CVE-2018-5391) became exploitable in the Linux kernel with the increase of the IP fragment reassembly queue size.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2018-5391"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-p6x5-xg7h-fj5h</id>
    <title>GHSA-p6x5-xg7h-fj5h</title>
    <updated>2026-10-02T17:07:42.584411+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The Linux kernel, versions 3.9+, is vulnerable to a denial of service attack with low rates of specially modified packets targeting IP fragment re-assembly. An attacker may cause a denial of service condition by sending specially crafted IP fragments. Various vulnerabilities in IP fragmentation have been discovered and fixed over the years. The current vulnerability (CVE-2018-5391) became exploitable in the Linux kernel with the increase of the IP fragment reassembly queue size.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-p6x5-xg7h-fj5h"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2018-5391</id>
    <title>gsd-2018-5391</title>
    <updated>2026-10-02T17:07:42.584428+00:00</updated>
    <content>gsd-2018-5391</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2018-5391"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-20-105-05</id>
    <title>ICSA-20-105-05 — Siemens RUGGEDCOM, SCALANCE, SIMATIC, SINEMA (Update B)</title>
    <updated>2026-10-02T17:07:42.584439+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can lead to a denial of service. Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can lead to a denial of service.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-20-105-05"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2018:2785</id>
    <title>RHSA-2018:2785 — Red Hat Security Advisory: kernel security and bug fix update</title>
    <updated>2026-10-02T17:07:42.584458+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: TCP segments with random offsets allow a remote denial of service (SegmentSmack) kernel: IP fragments with random offsets allow a remote denial of service (FragmentSmack) kernel: mm: use-after-free in do_get_mempolicy function allows local DoS or other unspecified impact</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2018:2785"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2018:3083</id>
    <title>RHSA-2018:3083 — Red Hat Security Advisory: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-02T17:07:42.584479+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: AIO write triggers integer overflow in some protocols kernel: Information leak when handling NM entries containing NUL kernel: Use-after-free in snd_pcm_info function in ALSA subsystem potentially leads to privilege escalation kernel: Handling of might_cancel queueing is not properly pretected against race kernel: Salsa20 encryption algorithm does not correctly handle zero-length inputs allowing local attackers to cause denial-of-service kernel: Inifinite loop vulnerability in mm/madvise.c:madvise_willneed() function allows local denial of service kernel: Mishandling mutex within libsas allowing local Denial of Service kernel: out-of-bounds access in the show_timer function in kernel/time/posix-timers.c kernel: Division by zero in change_port_settings in drivers/usb/serial/io_ti.c resulting in a denial of service kernel: NULL pointer dereference in ext4/mballoc.c:ext4_process_freed_data() when mounting crafted ext4 image kernel: NULL pointer dereference in ext4/xattr.c:ext4_xattr_inode_hash() causes crash with crafted ext4 image kernel: vhost: Information disclosure in vhost/vhost.c:vhost_new_msg() kernel: fuse-backed file mmap-ed onto process cmdline arguments causes denial of service kernel: a null pointer dereference in net/dccp/output.c:dccp_write_xmit() leads to a system crash kernel: drivers/block/loop.c mishandles lo_release serialization allowing denial-of-service kernel: IP fragments with random offsets allow a remote denial of service (FragmentSmack) kernel…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2018:3083"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2018:2344-1</id>
    <title>SUSE-SU-2018:2344-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-02T17:07:42.584550+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2018:2344-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-5391</id>
    <title>UBUNTU-CVE-2018-5391</title>
    <updated>2026-10-02T17:07:42.584572+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:14.04:LTS: linux, Ubuntu:14.04:LTS: linux-aws, Ubuntu:14.04:LTS: linux-lts-xenial, Ubuntu:16.04:LTS: linux, Ubuntu:16.04:LTS: linux-aws, Ubuntu:16.04:LTS: linux-azure, Ubuntu:16.04:LTS: linux-euclid, Ubuntu:16.04:LTS: linux-gcp, Ubuntu:16.04:LTS: linux-hwe, Ubuntu:16.04:LTS: linux-kvm and 18 more</p>
<p>The Linux kernel, versions 3.9+, is vulnerable to a denial of service attack with low rates of specially modified packets targeting IP fragment re-assembly. An attacker may cause a denial of service condition by sending specially crafted IP fragments. Various vulnerabilities in IP fragmentation have been discovered and fixed over the years. The current vulnerability (CVE-2018-5391) became exploitable in the Linux kernel with the increase of the IP fragment reassembly queue size.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-5391"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0508</id>
    <title>WID-SEC-W-2023-0508 — Linux Kernel: Schwachstelle ermöglicht Denial of Service</title>
    <updated>2026-10-02T17:07:42.584625+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0508"/>
  </entry>
</feed>
