#VU99986 Resource exhaustion in Linux kernel - CVE-2001-1244
Published: July 7, 2001 / Updated: November 6, 2024
Linux kernel
Linux Foundation
Description
The vulnerability allows a remote non-authenticated attacker to perform service disruption.
Multiple TCP implementations could allow remote attackers to cause a denial of service (bandwidth and CPU exhaustion) by setting the maximum segment size (MSS) to a very small number and requesting large amounts of data, which generates more packets with less TCP-level data that amplify network traffic and consume more server CPU to process.