CVE-2018-5391: Canonical Ubuntu Linux

High severity, CVSS 7.5. EPSS: 32.4% chance of exploitation in the next 30 days.

The Linux kernel, versions 3.9+, is vulnerable to a denial of service attack with low rates of specially modified packets targeting IP fragment re-assembly. An attacker may cause a denial of service condition by sending specially crafted IP fragments. Various vulnerabilities in IP fragmentation have been discovered and fixed over the years. The current vulnerability (CVE-2018-5391) became exploitable in the Linux kernel with the increase of the IP fragment reassembly queue size.

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 16.04 only; version 18.04 only
  • Debian Debian Linux: version 8.0 only; version 9.0 only
  • F5 BIG-IP Access Policy Manager: from 11.5.1, before 11.6.5.1 (fixed in 11.6.5.1); from 12.1.0, before 12.1.5 (fixed in 12.1.5); from 13.0.0, before 13.1.3 (fixed in 13.1.3); from 14.0.0, before 14.0.1.1 (fixed in 14.0.1.1); from 14.1.0, before 14.1.2.4 (fixed in 14.1.2.4)
  • F5 BIG-IP Advanced Firewall Manager: from 11.5.1, before 11.6.5.1 (fixed in 11.6.5.1); from 12.1.0, before 12.1.5 (fixed in 12.1.5); from 13.0.0, before 13.1.3 (fixed in 13.1.3); from 14.0.0, before 14.0.1.1 (fixed in 14.0.1.1); from 14.1.0, before 14.1.2.4 (fixed in 14.1.2.4)
  • F5 BIG-IP Analytics: from 11.5.1, before 11.6.5.1 (fixed in 11.6.5.1); from 12.1.0, before 12.1.5 (fixed in 12.1.5); from 13.0.0, before 13.1.3 (fixed in 13.1.3); from 14.0.0, before 14.0.1.1 (fixed in 14.0.1.1); from 14.1.0, before 14.1.2.4 (fixed in 14.1.2.4)
  • F5 BIG-IP Application Acceleration Manager: from 11.5.1, before 11.6.5.1 (fixed in 11.6.5.1); from 12.1.0, before 12.1.5 (fixed in 12.1.5); from 13.0.0, before 13.1.3 (fixed in 13.1.3); from 14.0.0, before 14.0.1.1 (fixed in 14.0.1.1); from 14.1.0, before 14.1.2.4 (fixed in 14.1.2.4)
  • F5 BIG-IP Application Security Manager: from 11.5.1, before 11.6.5.1 (fixed in 11.6.5.1); from 12.1.0, before 12.1.5 (fixed in 12.1.5); from 13.0.0, before 13.1.3 (fixed in 13.1.3); from 14.0.0, before 14.0.1.1 (fixed in 14.0.1.1); from 14.1.0, before 14.1.2.4 (fixed in 14.1.2.4)
  • F5 BIG-IP Domain Name System: from 11.5.1, before 11.6.5.1 (fixed in 11.6.5.1); from 12.1.0, before 12.1.5 (fixed in 12.1.5); from 13.0.0, before 13.1.3 (fixed in 13.1.3); from 14.0.0, before 14.0.1.1 (fixed in 14.0.1.1); from 14.1.0, before 14.1.2.4 (fixed in 14.1.2.4)
  • F5 BIG-IP Edge Gateway: from 11.5.1, before 11.6.5.1 (fixed in 11.6.5.1); from 12.1.0, before 12.1.5 (fixed in 12.1.5); from 13.0.0, before 13.1.3 (fixed in 13.1.3); from 14.0.0, before 14.0.1.1 (fixed in 14.0.1.1); from 14.1.0, before 14.1.2.4 (fixed in 14.1.2.4)
  • F5 BIG-IP Fraud Protection Service: from 11.5.1, before 11.6.5.1 (fixed in 11.6.5.1); from 12.1.0, before 12.1.5 (fixed in 12.1.5); from 13.0.0, before 13.1.3 (fixed in 13.1.3); from 14.0.0, before 14.0.1.1 (fixed in 14.0.1.1); from 14.1.0, before 14.1.2.4 (fixed in 14.1.2.4)
  • F5 BIG-IP Global Traffic Manager: from 11.5.1, before 11.6.5.1 (fixed in 11.6.5.1); from 12.1.0, before 12.1.5 (fixed in 12.1.5); from 13.0.0, before 13.1.3 (fixed in 13.1.3); from 14.0.0, before 14.0.1.1 (fixed in 14.0.1.1); from 14.1.0, before 14.1.2.4 (fixed in 14.1.2.4)
  • F5 BIG-IP Link Controller: from 11.5.1, before 11.6.5.1 (fixed in 11.6.5.1); from 12.1.0, before 12.1.5 (fixed in 12.1.5); from 13.0.0, before 13.1.3 (fixed in 13.1.3); from 14.0.0, before 14.0.1.1 (fixed in 14.0.1.1); from 14.1.0, before 14.1.2.4 (fixed in 14.1.2.4)
  • F5 BIG-IP Local Traffic Manager: from 11.5.1, before 11.6.5.1 (fixed in 11.6.5.1); from 12.1.0, before 12.1.5 (fixed in 12.1.5); from 13.0.0, before 13.1.3 (fixed in 13.1.3); from 14.0.0, before 14.0.1.1 (fixed in 14.0.1.1); from 14.1.0, before 14.1.2.4 (fixed in 14.1.2.4)
  • F5 BIG-IP Policy Enforcement Manager: from 11.5.1, before 11.6.5.1 (fixed in 11.6.5.1); from 12.1.0, before 12.1.5 (fixed in 12.1.5); from 13.0.0, before 13.1.3 (fixed in 13.1.3); from 14.0.0, before 14.0.1.1 (fixed in 14.0.1.1); from 14.1.0, before 14.1.2.4 (fixed in 14.1.2.4)
  • F5 BIG-IP Webaccelerator: from 11.5.1, before 11.6.5.1 (fixed in 11.6.5.1); from 12.1.0, before 12.1.5 (fixed in 12.1.5); from 13.0.0, before 13.1.3 (fixed in 13.1.3); from 14.0.0, before 14.0.1.1 (fixed in 14.0.1.1); from 14.1.0, before 14.1.2.4 (fixed in 14.1.2.4)
  • Linux Linux Kernel: from 3.9, up to and including 4.18
  • Microsoft Windows 10: affected versions not specified; version 1607 only; version 1703 only; version 1709 only; version 1803 only
  • Microsoft Windows 7: affected versions not specified
  • Microsoft Windows 8.1: affected versions not specified
  • Microsoft Windows Rt 8.1: affected versions not specified
  • Microsoft Windows Server 2008: affected versions not specified; version r2 only
  • Microsoft Windows Server 2012: affected versions not specified; version r2 only
  • Microsoft Windows Server 2016: affected versions not specified; version 1709 only; version 1803 only
  • Red Hat Enterprise Linux Desktop: version 6.0 only; version 7.0 only
  • Red Hat Enterprise Linux Server: version 6.0 only; version 7.0 only
  • and 26 more

Published 2018-09-06. Last modified 2026-06-17.