Back

HIGH

kernel: sctp: Fix kernel panic while process protocol violation parameter

Published Oct 20, 2008

Description

The Stream Control Transmission Protocol (sctp) implementation in the Linux kernel before 2.6.27 does not properly handle a protocol violation in which a parameter has an invalid length, which allows attackers to cause a denial of service (panic) via unspecified vectors, related to sctp_sf_violation_paramlen, sctp_sf_abort_violation, sctp_make_abort_violation, and incorrect data types in function calls.

Affected products

Remediation

Red Hat statement

The versions of Linux kernel as shipped with Red Hat Enterprise Linux 2.1, 3, 4, and 5 were not affected by this issue.

Metrics

References (15)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Oct 20, 2008
Updated Aug 7, 2024
Reserved Oct 20, 2008
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date Sep 30, 2008