Netflix has Identified Several TCP Networking Vulnerabilities in Linux kernels
Additionally, versions of the Linux kernel up to, and including, 4.14 require a second patch #1: Block connections with a low MSS using one of the supplied filters. On Linux kernels prior to 4.15, an attacker may be able to further exploit the fragmented queue to cause an expensive linked-list walk for subsequent SACKs received for that same TCP connection. An attacker may be able to further exploit the fragmented send map to cause an expensive linked-list walk for subsequent SACKs received for that same TCP connection.
Source: github.com