CVE-2018-18409: Canonical Ubuntu Linux

Medium severity, CVSS 5.5. EPSS: 1.3% chance of exploitation in the next 30 days.

A stack-based buffer over-read exists in setbit() at iptree.h of TCPFLOW 1.5.0, due to received incorrect values causing incorrect computation, leading to denial of service during an address_histogram call or a get_histogram call.

Affected products

Published 2018-10-17. Last modified 2026-06-17.