Back to search
CVE-2014-4667
Published: Jul 3, 2014
Modified: Aug 6, 2024
PUBLISHED
Description
The sctp_association_free function in net/sctp/associola.c in the Linux kernel before 3.15.2 does not properly manage a certain backlog value, which allows remote attackers to cause a denial of service (socket outage) via a crafted SCTP packet.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
SUSE-SU-2014:1316
vendor-advisory
x_refsource_SUSE
[oss-security] 20140627 Re: CVE request -- Linux kernel: sctp: sk_ack_backlog wrap-around problem
mailing-list
x_refsource_MLIST
59790
third-party-advisory
x_refsource_SECUNIA
USN-2335-1
vendor-advisory
x_refsource_UBUNTU
USN-2334-1
vendor-advisory
x_refsource_UBUNTU
SUSE-SU-2014:1319
vendor-advisory
x_refsource_SUSE
60564
third-party-advisory
x_refsource_SECUNIA
68224
vdb-entry
x_refsource_BID
59777
third-party-advisory
x_refsource_SECUNIA
60596
third-party-advisory
x_refsource_SECUNIA
http://linux.oracle.com/errata/ELSA-2014-3068.html
x_refsource_CONFIRM
http://linux.oracle.com/errata/ELSA-2014-3069.html
x_refsource_CONFIRM
https://bugzilla.redhat.com/show_bug.cgi?id=1113967
x_refsource_CONFIRM
http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.15.2
x_refsource_CONFIRM
DSA-2992
vendor-advisory
x_refsource_DEBIAN
SUSE-SU-2015:0812
vendor-advisory
x_refsource_SUSE
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now