Multiple TCP implementations could allow remote attackers to cause a denial of service (bandwidth and CPU exhaustion) by setting the maximum segment size (MSS) to a very small number and requesting large amounts of data, which generates more packets with less TCP-level data that amplify network traffic and consume more server CPU to process.
https://exchange.xforce.ibmcloud.com/vulnerabilities/6824
https://euvd.enisa.europa.eu/vulnerability/EUVD-2001-1225