Back

MEDIUM

kernel: DoS in sctp_addto_chunk in net/sctp/sm_make_chunk.c

Published Mar 25, 2022

Description

A flaw was found in the sctp_make_strreset_req function in net/sctp/sm_make_chunk.c in the SCTP network protocol in the Linux kernel with a local user privilege access. In this flaw, an attempt to use more buffer than is allocated triggers a BUG_ON issue, leading to a denial of service (DOS).

Affected products

Remediation

Red Hat mitigation

Mitigation for this issue is to skip loading the affected module SCTP onto the system. Until we have a fix available, this can be done by a blacklist mechanism and will ensure the driver is not loaded at the boot time. ~~~ How do I blacklist a kernel module to prevent it from loading automatically? https://access.redhat.com/solutions/41278 ~~~

Weaknesses (2)

References (7)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner redhat
Published Mar 25, 2022
Updated Aug 2, 2024
Reserved Jan 20, 2022

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Moderate
Public date Oct 14, 2021
Bugzilla 2042822

ENISA EUVD

Assigner redhat
Published Mar 25, 2022
Updated Aug 2, 2024

GitHub

No data