CVE-2018-5390: a10networks Advanced Core Operating System

High severity, CVSS 7.5. EPSS: 73.7% chance of exploitation in the next 30 days.

Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can lead to a denial of service.

Affected products

  • a10networks Advanced Core Operating System: version 3.2.2 only; version 4.1.0 only; version 4.1.1 only; version 4.1.2 only; version 4.1.4 only
  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 16.04 only; version 18.04 only
  • Cisco Collaboration Meeting Rooms: version 1.0 only
  • Cisco Digital Network Architecture Center: version 1.2 only
  • Cisco Expressway: version x8.10 only; version x8.10.1 only; version x8.10.2 only; version x8.10.3 only; version x8.10.4 only; version x8.11 only
  • Cisco Expressway Series: affected versions not specified
  • Cisco Meeting Management: version 1.0 only; version 1.0.1 only
  • Cisco Network Assurance Engine: version 2.1(1a) only
  • Cisco Telepresence Conductor Firmware: version xc4.3 only; version xc4.3.1 only; version xc4.3.2 only; version xc4.3.3 only; version xc4.3.4 only
  • Cisco Telepresence Video Communication Server Firmware: version x8.10 only; version x8.10.1 only; version x8.10.2 only; version x8.10.3 only; version x8.10.4 only; version x8.11 only
  • Cisco Threat Grid-Cloud: affected versions not specified
  • Cisco Webex Hybrid Data Security: affected versions not specified
  • Cisco Webex Video Mesh: affected versions not specified
  • Debian Debian Linux: version 8.0 only; version 9.0 only
  • F5 BIG-IP Access Policy Manager: from 11.5.1, up to and including 11.6.3; from 12.1.0, up to and including 12.1.3; from 13.0.0, up to and including 13.1.1; version 14.0.0 only
  • F5 BIG-IP Advanced Firewall Manager: from 11.5.1, up to and including 11.6.3; from 12.1.0, up to and including 12.1.3; from 13.0.0, up to and including 13.1.1; version 14.0.0 only
  • F5 BIG-IP Analytics: from 11.5.1, up to and including 11.6.3; from 12.1.0, up to and including 12.1.3; from 13.0.0, up to and including 13.1.1; version 14.0.0 only
  • F5 BIG-IP Application Acceleration Manager: from 11.5.1, up to and including 11.6.3; from 12.1.0, up to and including 12.1.3; from 13.0.0, up to and including 13.1.1; version 14.0.0 only
  • F5 BIG-IP Application Security Manager: from 11.5.1, up to and including 11.6.3; from 12.1.0, up to and including 12.1.3; from 13.0.0, up to and including 13.1.1; version 14.0.0 only
  • F5 BIG-IP Domain Name System: from 11.5.1, up to and including 11.6.3; from 12.1.0, up to and including 12.1.3; from 13.0.0, up to and including 13.1.1; version 14.0.0 only
  • F5 BIG-IP Edge Gateway: from 11.5.1., up to and including 11.6.3; from 12.1.0, up to and including 12.1.3; from 13.0.0, up to and including 13.1.1; version 14.0.0 only
  • F5 BIG-IP Fraud Protection Service: from 11.5.1, up to and including 11.6.3; from 12.1.0, up to and including 12.1.3; from 13.0.0, up to and including 13.1.1; version 14.0.0 only
  • F5 BIG-IP Global Traffic Manager: from 11.5.1, up to and including 11.6.3; from 12.1.0, up to and including 12.1.3; from 13.0.0, up to and including 13.1.1; version 14.0.0 only
  • F5 BIG-IP Link Controller: from 11.5.1, up to and including 11.6.3; from 12.1.0, up to and including 12.1.3; from 13.0.0, up to and including 13.1.1; version 14.0.0 only
  • F5 BIG-IP Local Traffic Manager: from 11.5.1, up to and including 11.6.3; from 12.0.0, up to and including 12.1.3; after 13.0.0, up to and including 13.1.1; version 14.0.0 only
  • and 13 more

Published 2018-08-06. Last modified 2026-06-17.