security flaw
Published Jun 30, 2006
5.0
MEDIUMCVSS 2.0
EPSS 5.20%
Description
SCTP conntrack (ip_conntrack_proto_sctp.c) in netfilter for Linux kernel 2.6.17 before 2.6.17.3 and 2.6.16 before 2.6.16.23 allows remote attackers to cause a denial of service (crash) via a packet without any chunks, which causes a variable to contain an invalid value that is later used to dereference a pointer.
Affected products
No data.
- 2.6.16
- 2.6.16.1
- 2.6.16.2
- 2.6.16.10
- 2.6.16.11
- 2.6.16.12
- 2.6.16.13
- 2.6.16.14
- 2.6.16.15
- 2.6.16.16
- 2.6.16.17
- 2.6.16.18
- 2.6.16.19
- 2.6.16.20
- 2.6.16.21
- 2.6.16.22
- 2.6.17
- 2.6.17.1
- 2.6.17.2
No data.
Red Hat Enterprise Linux 4
kernel-0:2.6.9-42.EL
Fixed · RHSA-2006:0575
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 4 | kernel-0:2.6.9-42.EL | Fixed | RHSA-2006:0575 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (16 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 5.20% (0.05198) | 92.22th | v5 (v2026.06.15) |
| Jun 15, 2026 | 5.10% (0.05102) | 91.25th | v5 (v2026.06.15) |
| Jul 24, 2025 | 23.28% (0.23284) | 95.69th | v4 (v2025.03.14) |
| Mar 30, 2025 | 19.69% (0.19689) | 94.95th | v4 (v2025.03.14) |
| Mar 29, 2025 | 16.09% (0.16093) | 91.37th | v4 (v2025.03.14) |
| Mar 17, 2025 | 19.69% (0.19689) | 94.96th | v4 (v2025.03.14) |
| Dec 17, 2024 | 19.11% (0.19114) | 96.26th | v3 (v2023.03.01) |
| Nov 23, 2023 | 17.98% (0.17976) | 95.65th | v3 (v2023.03.01) |
| Aug 26, 2023 | 13.54% (0.13539) | 94.90th | v3 (v2023.03.01) |
| Jun 11, 2023 | 14.28% (0.14281) | 94.91th | v3 (v2023.03.01) |
| May 4, 2023 | 13.56% (0.13557) | 94.74th | v3 (v2023.03.01) |
| Mar 27, 2023 | 14.29% (0.14290) | 94.83th | v3 (v2023.03.01) |
| Mar 7, 2023 | 14.38% (0.14376) | 94.81th | v3 (v2023.03.01) |
| Mar 6, 2023 | 4.36% (0.04358) | 88.02th | v2 (v2022.01.01) |
| Apr 1, 2022 | 4.36% (0.04358) | 86.83th | v2 (v2022.01.01) |
| Feb 4, 2022 | 4.36% (0.04358) | 70.59th | v2 (v2022.01.01) |
References (32)
- http://secunia.com/advisories/20917 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/20986 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/21179 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/21298 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/21465 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/21498 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/21614 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/21934 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/22417 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://support.avaya.com/elmodocs2/security/ASA-2006-200.htm x_refsource_CONFIRM
- http://www.kb.cert.org/vuls/id/717844 third-party-advisoryx_refsource_CERT-VNUS Government Resource
- http://www.kernel.org/git/?p=linux/kernel/git/stable/linux-2.6.17.y.git%3Ba=commit%3Bh=9c48e1ea8cf8800cc5e2d39ccbb8b5ff9704f8e9 x_refsource_CONFIRM
- http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.23 x_refsource_CONFIRM
- http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.17.3 x_refsource_CONFIRM
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:151 vendor-advisoryx_refsource_MANDRIVA
- http://www.novell.com/linux/security/advisories/2006_42_kernel.html vendor-advisoryx_refsource_SUSE
- http://www.novell.com/linux/security/advisories/2006_47_kernel.html vendor-advisoryx_refsource_SUSE
- http://www.osvdb.org/26963 vdb-entryx_refsource_OSVDB
- http://www.redhat.com/support/errata/RHSA-2006-0575.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/archive/1/439483/100/100/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/439610/100/100/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/18755 vdb-entryx_refsource_BID
- http://www.ubuntu.com/usn/usn-331-1 vendor-advisoryx_refsource_UBUNTU
- http://www.ubuntu.com/usn/usn-346-1 vendor-advisoryx_refsource_UBUNTU
- http://www.vupen.com/english/advisories/2006/2623 vdb-entryx_refsource_VUPENVendor Advisory
- https://access.redhat.com/security/cve/CVE-2006-2934 Vendor Advisory
- https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=197387 x_refsource_CONFIRMPatch
- https://bugzilla.redhat.com/show_bug.cgi?id=1618126 Issue Tracking
- https://issues.rpath.com/browse/RPL-488 x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2006-2934
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10932 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2006-2934
Change history (0)
No recorded changes yet.