Tuesday, March 19, 2019

IBM Security Bulletin: This Power System update is being released to address CVE-2018-5391

Mar 19, 2019 10:00 am EDT

Categorized: High Severity

Share this post:

Power9: In response to a denial of service vulnerability, a new Power Systems firmware update is being released to address Common Vulnerabilities and Exposures issue number CVE-2018-5391. A remote attacker could use large IP frames to trigger time and calculation expensive calls in the reassembly of the packets. This could could lead to CPU saturation and possible reset and termination of the service processor. Changes were made to lower the IP fragment threshold values to prevent the attack.

CVE(s): CVE-2018-5391

Affected product(s) and affected version(s):
Firmware release FW920 is affected.

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: https://www-01.ibm.com/support/docview.wss?uid=ibm10873156
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/148388



from IBM Product Security Incident Response Team https://ift.tt/2JmfpdT

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.