AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2018-5391

HIGH · CVSS 7.5 EPSS 32.45% Public Exploit

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2018-09-06 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

Exhibit — Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2018-5391
Severity
HIGH
CVSS
7.5
EPSS
32.45%
Linux

Original Filing — NVD Description

The Linux kernel, versions 3.9+, is vulnerable to a denial of service attack with low rates of specially modified packets targeting IP fragment re-assembly. An attacker may cause a denial of service condition by sending specially crafted IP fragments. Various vulnerabilities in IP fragmentation have been discovered and fixed over the years. The current vulnerability (CVE-2018-5391) became exploitable in the Linux kernel with the increase of the IP fragment reassembly queue size.