Mar 19, 2019 10:00 am EDT
Categorized: High Severity
Share this post:
Power9: In response to a denial of service vulnerability, a new Power Systems firmware update is being released to address Common Vulnerabilities and Exposures issue number CVE-2018-5391. A remote attacker could use large IP frames to trigger time and calculation expensive calls in the reassembly of the packets. This could could lead to CPU saturation and possible reset and termination of the service processor. Changes were made to lower the IP fragment threshold values to prevent the attack.
CVE(s): CVE-2018-5391
Affected product(s) and affected version(s):
Firmware release FW920 is affected.
Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: https://www-01.ibm.com/support/docview.wss?uid=ibm10873156
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/148388
from IBM Product Security Incident Response Team https://ift.tt/2JmfpdT
No comments:
Post a Comment
Note: Only a member of this blog may post a comment.