CVE-2006-2275
Linux SCTP (lksctp) before 2.6.17 allows remote attackers to cause a denial of service (deadlock) via a large number of small messages to a receiver application that cannot process the messages quickly enough, which leads to "spillover of the receive…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.60%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Linux SCTP (lksctp) before 2.6.17 allows remote attackers to cause a denial of service (deadlock) via a large number of small messages to a receiver application that cannot process the messages quickly enough, which leads to "spillover of the receive buffer."
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 3.60% probability · 89th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-667
- Affected
- lksctp/stream control transmission protocol · canonical/ubuntu linux
- Source
- cve@mitre.org
References
- http://git.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=7c3ceb4fb9667f34f1599a062efecf4cdc4a4ce5Broken Link
- http://secunia.com/advisories/20716Broken Link
- http://secunia.com/advisories/21465Broken Link
- http://secunia.com/advisories/22417Broken Link
- http://support.avaya.com/elmodocs2/security/ASA-2006-200.htmThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2006-0575.htmlBroken Link
- http://www.securityfocus.com/bid/17955Broken Link, Third Party Advisory, VDB Entry
- http://www.trustix.org/errata/2006/0026Broken Link
- http://www.ubuntu.com/usn/usn-302-1Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26433Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11295Broken Link
- http://git.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=7c3ceb4fb9667f34f1599a062efecf4cdc4a4ce5Broken Link
- http://secunia.com/advisories/20716Broken Link
- http://secunia.com/advisories/21465Broken Link
- http://secunia.com/advisories/22417Broken Link
- http://support.avaya.com/elmodocs2/security/ASA-2006-200.htmThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2006-0575.htmlBroken Link
- http://www.securityfocus.com/bid/17955Broken Link, Third Party Advisory, VDB Entry
- http://www.trustix.org/errata/2006/0026Broken Link
- http://www.ubuntu.com/usn/usn-302-1Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26433Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11295Broken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.