# CVE-2018-14641

## Summary

- **CVE ID:** CVE-2018-14641
- **Severity:** MEDIUM
- **CVSS Score:** 6.5 (CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
- **CWE:** CWE-456
- **Published:** Sep 18, 2018
- **Last Modified:** Mar 14, 2026

## Description

A security flaw was found in the ip_frag_reasm() function in net/ipv4/ip_fragment.c in the Linux kernel from 4.19-rc1 to 4.19-rc3 inclusive, which can cause a later system crash in ip_do_fragment(). With certain non-default, but non-rare, configuration of a victim host, an attacker can trigger this crash remotely, thus leading to a remote denial-of-service.

## Affected Products

- The Linux Foundation — kernel (from 4.19-rc1 to 4.19-rc3 inclusive)

## References

- [CNA](https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=5d407b071dc369c26a38398326ee2be53651cfe4)
- [CNA](https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14641)
- [CNA](https://access.redhat.com/errata/RHSA-2018:2948)
- [CNA](https://seclists.org/oss-sec/2018/q3/248)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 1.35%
- **EPSS Percentile:** 79.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-12._