kernel: sctp remote denial of service
Published Mar 19, 2010
7.8
HIGHCVSS 2.0
EPSS 4.48%
Description
The sctp_rcv_ootb function in the SCTP implementation in the Linux kernel before 2.6.23 allows remote attackers to cause a denial of service (infinite loop) via (1) an Out Of The Blue (OOTB) chunk or (2) a chunk of zero length.
Affected products
No data.
- ≤ 2.6.22.19
- 2.6
- 2.6.0
- 2.6.1
- 2.6.2
- 2.6.10
- 2.6.11
- 2.6.11.1
- 2.6.11.2
- 2.6.11.3
- 2.6.11.4
- 2.6.11.5
- 2.6.11.6
- 2.6.11.7
- 2.6.11.8
- 2.6.11.9
- 2.6.11.10
- 2.6.11.11
- 2.6.11.12
- 2.6.12
- 2.6.12.1
- 2.6.12.2
- 2.6.12.3
- 2.6.12.4
- 2.6.12.5
- 2.6.12.6
- 2.6.13
- 2.6.13.1
- 2.6.13.2
- 2.6.13.3
- 2.6.13.4
- 2.6.13.5
- 2.6.14
- 2.6.14.1
- 2.6.14.2
- 2.6.14.3
- 2.6.14.4
- 2.6.14.5
- 2.6.14.6
- 2.6.14.7
- 2.6.15
- 2.6.15.1
- 2.6.15.2
- 2.6.15.3
- 2.6.15.4
- 2.6.15.5
- 2.6.15.6
- 2.6.15.7
- 2.6.16
- 2.6.16.1
- 2.6.16.2
- 2.6.16.3
- 2.6.16.4
- 2.6.16.5
- 2.6.16.6
- 2.6.16.7
- 2.6.16.8
- 2.6.16.9
- 2.6.16.10
- 2.6.16.11
- 2.6.16.12
- 2.6.16.13
- 2.6.16.14
- 2.6.16.15
- 2.6.16.16
- 2.6.16.17
- 2.6.16.18
- 2.6.16.19
- 2.6.16.20
- 2.6.16.21
- 2.6.16.22
- 2.6.16.23
- 2.6.16.24
- 2.6.16.25
- 2.6.16.26
- 2.6.16.27
- 2.6.16.28
- 2.6.16.29
- 2.6.16.30
- 2.6.16.31
- 2.6.16.32
- 2.6.16.33
- 2.6.16.34
- 2.6.16.35
- 2.6.16.36
- 2.6.16.37
- 2.6.16.38
- 2.6.16.39
- 2.6.16.40
- 2.6.16.41
- 2.6.16.42
- 2.6.16.43
- 2.6.16.44
- 2.6.16.45
- 2.6.16.46
- 2.6.16.47
- 2.6.16.48
- 2.6.16.49
- 2.6.16.50
- 2.6.16.51
- 2.6.16.52
- 2.6.16.53
- 2.6.16.54
- 2.6.16.55
- 2.6.16.56
- 2.6.16.57
- 2.6.16.58
- 2.6.16.59
- 2.6.16.60
- 2.6.16.61
- 2.6.16.62
- 2.6.17
- 2.6.17.1
- 2.6.17.2
- 2.6.17.3
- 2.6.17.4
- 2.6.17.5
- 2.6.17.6
- 2.6.17.7
- 2.6.17.8
- 2.6.17.9
- 2.6.17.10
- 2.6.17.11
- 2.6.17.12
- 2.6.17.13
- 2.6.17.14
- 2.6.18
- 2.6.18
- 2.6.18
- 2.6.18
- 2.6.18
- 2.6.18
- 2.6.18
- 2.6.18
- 2.6.18.1
- 2.6.18.2
- 2.6.18.3
- 2.6.18.4
- 2.6.18.5
- 2.6.18.6
- 2.6.18.7
- 2.6.18.8
- 2.6.19
- 2.6.19.1
- 2.6.19.2
- 2.6.19.3
- 2.6.19.4
- 2.6.19.5
- 2.6.19.6
- 2.6.19.7
- 2.6.20
- 2.6.20.1
- 2.6.20.2
- 2.6.20.3
- 2.6.20.4
- 2.6.20.5
- 2.6.20.6
- 2.6.20.7
- 2.6.20.8
- 2.6.20.9
- 2.6.20.10
- 2.6.20.11
- 2.6.20.12
- 2.6.20.13
- 2.6.20.14
- 2.6.20.15
- 2.6.20.16
- 2.6.20.17
- 2.6.20.18
- 2.6.20.19
- 2.6.20.20
- 2.6.20.21
- 2.6.21
- 2.6.21.1
- 2.6.21.2
- 2.6.21.3
- 2.6.21.4
- 2.6.21.5
- 2.6.21.6
- 2.6.21.7
- 2.6.22
- 2.6.22.1
- 2.6.22.2
- 2.6.22.3
- 2.6.22.4
- 2.6.22.5
- 2.6.22.6
- 2.6.22.7
- 2.6.22.8
- 2.6.22.9
- 2.6.22.10
- 2.6.22.11
- 2.6.22.12
- 2.6.22.13
- 2.6.22.14
- 2.6.22.15
- 2.6.22.16
- 2.6.22.17
- 2.6.22.18
No data.
Red Hat Enterprise Linux 4
kernel-0:2.6.9-89.0.23.EL
Fixed · RHSA-2010:0146
Red Hat Enterprise Linux 4.7 Z Stream
kernel-0:2.6.9-78.0.30.EL
Fixed · RHSA-2010:0342
Red Hat Enterprise Linux 5
kernel-0:2.6.18-164.15.1.el5
Fixed · RHSA-2010:0147
Red Hat Enterprise Linux 5.2 Z Stream
kernel-0:2.6.18-92.1.38.el5
Fixed · RHSA-2010:0148
Red Hat Enterprise Linux 5.3.Z - Server Only
kernel-0:2.6.18-128.14.1.el5
Fixed · RHSA-2010:0149
Red Hat Enterprise Virtualization for RHEL-5
rhev-hypervisor-0:5.4-2.1.10.el5_4rhev2_1
Fixed · RHSA-2010:0172
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 4 | kernel-0:2.6.9-89.0.23.EL | Fixed | RHSA-2010:0146 |
| Red Hat Enterprise Linux 4.7 Z Stream | kernel-0:2.6.9-78.0.30.EL | Fixed | RHSA-2010:0342 |
| Red Hat Enterprise Linux 5 | kernel-0:2.6.18-164.15.1.el5 | Fixed | RHSA-2010:0147 |
| Red Hat Enterprise Linux 5.2 Z Stream | kernel-0:2.6.18-92.1.38.el5 | Fixed | RHSA-2010:0148 |
| Red Hat Enterprise Linux 5.3.Z - Server Only | kernel-0:2.6.18-128.14.1.el5 | Fixed | RHSA-2010:0149 |
| Red Hat Enterprise Virtualization for RHEL-5 | rhev-hypervisor-0:5.4-2.1.10.el5_4rhev2_1 | Fixed | RHSA-2010:0172 |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue did not affect the version of Linux kernel as shipped with Red Hat Enterprise Linux 3 as it did not include support for SCTP. It did not affect the version of Linux kernel as shipped with Red Hat Enterprise MRG as it has already had the fix to this issue.
References (15)
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=ece25dfa0991f65c4e1d26beb1c3c45bda4239b8 x_refsource_CONFIRM
- http://secunia.com/advisories/39295 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/43315 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.23 x_refsource_CONFIRM
- http://www.openwall.com/lists/oss-security/2010/03/17/2 mailing-listx_refsource_MLISTPatch
- http://www.redhat.com/support/errata/RHSA-2010-0147.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2010-0342.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/archive/1/516397/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.vmware.com/security/advisories/VMSA-2011-0003.html x_refsource_CONFIRM
- https://access.redhat.com/security/cve/CVE-2010-0008 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=555658 x_refsource_CONFIRMIssue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2010-0008
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11160 vdb-entrysignaturex_refsource_OVAL
- https://rhn.redhat.com/errata/RHSA-2010-0146.html vendor-advisoryx_refsource_REDHAT
- https://www.cve.org/CVERecord?id=CVE-2010-0008
Change history (0)
No recorded changes yet.