kernel: sctp: duplicate cookie handling NULL pointer dereference
Published Jul 4, 2013
5.4
MEDIUMCVSS 2.0
EPSS 4.71%
Description
The sctp_sf_do_5_2_4_dupcook function in net/sctp/sm_statefuns.c in the SCTP implementation in the Linux kernel before 3.8.5 does not properly handle associations during the processing of a duplicate COOKIE ECHO chunk, which allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via crafted SCTP traffic.
Affected products
No data.
- ≤ 3.8.4
- 3.0
- 3.0
- 3.0
- 3.0
- 3.0
- 3.0
- 3.0
- 3.0.1
- 3.0.2
- 3.0.3
- 3.0.4
- 3.0.5
- 3.0.6
- 3.0.7
- 3.0.8
- 3.0.9
- 3.0.10
- 3.0.11
- 3.0.12
- 3.0.13
- 3.0.14
- 3.0.15
- 3.0.16
- 3.0.17
- 3.0.18
- 3.0.19
- 3.0.20
- 3.0.21
- 3.0.22
- 3.0.23
- 3.0.24
- 3.0.25
- 3.0.26
- 3.0.27
- 3.0.28
- 3.0.29
- 3.0.30
- 3.0.31
- 3.0.32
- 3.0.33
- 3.0.34
- 3.0.35
- 3.0.36
- 3.0.37
- 3.0.38
- 3.0.39
- 3.0.40
- 3.0.41
- 3.0.42
- 3.0.43
- 3.0.44
- 3.0.45
- 3.0.46
- 3.0.47
- 3.0.48
- 3.0.49
- 3.0.50
- 3.0.51
- 3.0.52
- 3.0.53
- 3.0.54
- 3.0.55
- 3.0.56
- 3.0.57
- 3.0.58
- 3.0.59
- 3.0.60
- 3.0.61
- 3.0.62
- 3.0.63
- 3.0.64
- 3.0.65
- 3.0.66
- 3.0.67
- 3.0.68
- 3.1
- 3.1
- 3.1
- 3.1
- 3.1
- 3.1.1
- 3.1.2
- 3.1.3
- 3.1.4
- 3.1.5
- 3.1.6
- 3.1.7
- 3.1.8
- 3.1.9
- 3.1.10
- 3.2
- 3.2
- 3.2
- 3.2
- 3.2
- 3.2
- 3.2
- 3.2
- 3.2.1
- 3.2.1
- 3.2.2
- 3.2.3
- 3.2.4
- 3.2.5
- 3.2.6
- 3.2.7
- 3.2.8
- 3.2.9
- 3.2.10
- 3.2.11
- 3.2.12
- 3.2.13
- 3.2.14
- 3.2.15
- 3.2.16
- 3.2.17
- 3.2.18
- 3.2.19
- 3.2.20
- 3.2.21
- 3.2.22
- 3.2.23
- 3.2.24
- 3.2.25
- 3.2.26
- 3.2.27
- 3.2.28
- 3.2.29
- 3.2.30
- 3.3
- 3.3
- 3.3
- 3.3
- 3.3
- 3.3
- 3.3
- 3.3
- 3.3.1
- 3.3.2
- 3.3.3
- 3.3.4
- 3.3.5
- 3.3.6
- 3.3.7
- 3.3.8
- 3.4
- 3.4
- 3.4
- 3.4
- 3.4
- 3.4
- 3.4
- 3.4
- 3.4
- 3.4
- 3.4
- 3.4
- 3.4
- 3.4
- 3.4
- 3.4
- 3.4.1
- 3.4.1
- 3.4.2
- 3.4.2
- 3.4.3
- 3.4.3
- 3.4.4
- 3.4.4
- 3.4.5
- 3.4.5
- 3.4.6
- 3.4.7
- 3.4.8
- 3.4.9
- 3.4.10
- 3.4.11
- 3.4.12
- 3.4.13
- 3.4.14
- 3.4.15
- 3.4.16
- 3.4.17
- 3.4.18
- 3.4.19
- 3.4.20
- 3.4.21
- 3.4.22
- 3.4.23
- 3.4.24
- 3.4.25
- 3.4.26
- 3.4.27
- 3.4.28
- 3.4.29
- 3.4.30
- 3.4.31
- 3.4.32
- 3.5.1
- 3.5.2
- 3.5.3
- 3.5.4
- 3.5.5
- 3.5.6
- 3.5.7
- 3.6
- 3.6.1
- 3.6.2
- 3.6.3
- 3.6.4
- 3.6.5
- 3.6.6
- 3.6.7
- 3.6.8
- 3.6.9
- 3.6.10
- 3.6.11
- 3.7
- 3.7.1
- 3.7.2
- 3.7.3
- 3.7.4
- 3.7.5
- 3.7.6
- 3.7.7
- 3.7.8
- 3.7.9
- 3.7.10
- 3.8.0
- 3.8.1
- 3.8.2
- 3.8.3
No data.
OpenStack 3 for RHEL 6
kernel-0:2.6.32-358.118.1.openstack.el6
Fixed · RHSA-2013:1195
Red Hat Enterprise Linux 5
kernel-0:2.6.18-348.16.1.el5
Fixed · RHSA-2013:1166
Red Hat Enterprise Linux 6
kernel-0:2.6.32-358.18.1.el6
Fixed · RHSA-2013:1173
Red Hat Enterprise MRG 2
realtime-kernel
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| OpenStack 3 for RHEL 6 | kernel-0:2.6.32-358.118.1.openstack.el6 | Fixed | RHSA-2013:1195 |
| Red Hat Enterprise Linux 5 | kernel-0:2.6.18-348.16.1.el5 | Fixed | RHSA-2013:1166 |
| Red Hat Enterprise Linux 6 | kernel-0:2.6.32-358.18.1.el6 | Fixed | RHSA-2013:1173 |
| Red Hat Enterprise MRG 2 | realtime-kernel | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue does affect Linux kernel packages as shipped with Red Hat Enterprise Linux 5 and 6. This issue does not affect Linux kernel packages as shipped with Red Hat Enterprise MRG 2 as they already contain the fix.
References (18)
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=f2815633504b442ca0b0605c16bf3d88a3a0fcea x_refsource_CONFIRM
- http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00020.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00021.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00023.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00024.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-updates/2013-12/msg00129.html vendor-advisoryx_refsource_SUSE
- http://rhn.redhat.com/errata/RHSA-2013-1166.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2013-1173.html vendor-advisoryx_refsource_REDHAT
- http://www.debian.org/security/2013/dsa-2766 vendor-advisoryx_refsource_DEBIAN
- http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.8.5 x_refsource_CONFIRM
- http://www.openwall.com/lists/oss-security/2013/06/21/1 mailing-listx_refsource_MLIST
- http://www.ubuntu.com/usn/USN-1939-1 vendor-advisoryx_refsource_UBUNTU
- https://access.redhat.com/security/cve/CVE-2013-2206 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=976562 x_refsource_CONFIRMIssue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2013-2161 Advisory
- https://github.com/torvalds/linux/commit/f2815633504b442ca0b0605c16bf3d88a3a0fcea x_refsource_CONFIRMExploitPatch
- https://nvd.nist.gov/vuln/detail/CVE-2013-2206
- https://www.cve.org/CVERecord?id=CVE-2013-2206
Change history (0)
No recorded changes yet.