VulnerabilityModified
CVE-2021-3772
A blind attacker may be able to kill an existing SCTP association through invalid chunks if the attacker knows the IP-addresses and port numbers being used and the attacker can send packets with spoofed IP addresses.
MEDIUM 6.5EPSS 1.24%
Does this matter?
Lower severity and a low EPSS score (1.24%). Track it; it rarely justifies an emergency change on its own.
Description
A flaw was found in the Linux SCTP stack. A blind attacker may be able to kill an existing SCTP association through invalid chunks if the attacker knows the IP-addresses and port numbers being used and the attacker can send packets with spoofed IP addresses.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
- EPSS
- 1.24% probability · 67th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-354
- Affected
- linux/linux kernel · redhat/enterprise linux · debian/debian linux · oracle/communications cloud native core binding support function · oracle/communications cloud native core network exposure function · oracle/communications cloud native core policy · netapp/e-series santricity os controller · netapp/solidfire \& hci management node · netapp/solidfire \& hci storage node · netapp/hci compute node · netapp/h300s firmware · netapp/h500s firmware · netapp/h700s firmware · netapp/h410s firmware · netapp/h410c firmware · netapp/h610c firmware · netapp/h610s firmware · netapp/h615c firmware
- Source
- secalert@redhat.com
References
- https://bugzilla.redhat.com/show_bug.cgi?id=2000694Issue Tracking, Patch, Third Party Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=32f8807a48ae55be0e76880cfe8607a18b5bb0dfMailing List, Patch, Vendor Advisory
- https://github.com/torvalds/linux/commit/32f8807a48ae55be0e76880cfe8607a18b5bb0dfPatch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/03/msg00012.htmlMailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20221007-0001/Third Party Advisory
- https://ubuntu.com/security/CVE-2021-3772Patch, Third Party Advisory
- https://www.debian.org/security/2022/dsa-5096Third Party Advisory
- https://www.oracle.com/security-alerts/cpujul2022.htmlPatch, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2000694Issue Tracking, Patch, Third Party Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=32f8807a48ae55be0e76880cfe8607a18b5bb0dfMailing List, Patch, Vendor Advisory
- https://github.com/torvalds/linux/commit/32f8807a48ae55be0e76880cfe8607a18b5bb0dfPatch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/03/msg00012.htmlMailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20221007-0001/Third Party Advisory
- https://ubuntu.com/security/CVE-2021-3772Patch, Third Party Advisory
- https://www.debian.org/security/2022/dsa-5096Third Party Advisory
- https://www.oracle.com/security-alerts/cpujul2022.htmlPatch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.