udp_gro_receive_segment in net/ipv4/udp_offload.c in the Linux kernel 5.x before 5.0.13 allows remote attackers to cause a denial of service (slab-out-of-bounds memory corruption) or possibly have unspecified other impact via UDP packets with a 0 payload, because of mishandling of padded packets, aka the "GRO packet of death" issue.
| Software | From | Fixed in |
|---|---|---|
| linux / linux_kernel | 5.0 | 5.0.13 |
| canonical / ubuntu_linux | 19.04 | 19.04.x |