Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can lead to a denial of service.
3.13.0-155.2054.4.0-1027.304.4.0-133.159~14.04.14.4.0-133.1594.4.0-1065.754.15.0-1019.19~16.04.14.4.0-9029.314.15.0-1015.15~16.04.14.15.0-30.32~16.04.14.4.0-1031.37Exploitability
AV:NAC:LPR:NUI:NScope
S:UImpact
C:NI:NA:HCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H