Back

HIGH

kernel: sctp remote denial of service

Published Mar 19, 2010

Description

The sctp_rcv_ootb function in the SCTP implementation in the Linux kernel before 2.6.23 allows remote attackers to cause a denial of service (infinite loop) via (1) an Out Of The Blue (OOTB) chunk or (2) a chunk of zero length.

Affected products

Remediation

Red Hat statement

This issue did not affect the version of Linux kernel as shipped with Red Hat Enterprise Linux 3 as it did not include support for SCTP. It did not affect the version of Linux kernel as shipped with Red Hat Enterprise MRG as it has already had the fix to this issue.

References (15)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Mar 19, 2010
Updated Aug 7, 2024
Reserved Dec 14, 2009
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date Mar 16, 2010