Race condition in the sctp_rcv function in net/sctp/input.c in the Linux kernel before 2.6.29 allows remote attackers to cause a denial of service (system hang) via SCTP packets. NOTE: in some environments, this issue exists because of an incomplete fix for CVE-2011-2482.
2013-06-08T13:05:55.537
2025-04-11T00:51:21.963
Deferred
CVSSv2: 7.1 (HIGH)
AV:N/AC:M/Au:N/C:N/I:N/A:C
8.6
6.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | linux | linux_kernel | ≤ 2.6.28.10 | Yes |
Operating System | linux | linux_kernel | 2.6.28 | Yes |
Operating System | linux | linux_kernel | 2.6.28.1 | Yes |
Operating System | linux | linux_kernel | 2.6.28.2 | Yes |
Operating System | linux | linux_kernel | 2.6.28.3 | Yes |
Operating System | linux | linux_kernel | 2.6.28.4 | Yes |
Operating System | linux | linux_kernel | 2.6.28.5 | Yes |
Operating System | linux | linux_kernel | 2.6.28.6 | Yes |
Operating System | linux | linux_kernel | 2.6.28.7 | Yes |
Operating System | linux | linux_kernel | 2.6.28.8 | Yes |
Operating System | linux | linux_kernel | 2.6.28.9 | Yes |