The SCTP socket buffer used by a userspace application is not accounted by the cgroups subsystem. An attacker can use this flaw to cause a denial of service attack. Kernel 3.10.x and 4.18.x branches are believed to be vulnerable.
2019-03-25T19:29:01.993
2024-11-21T04:42:46.240
Modified
CVSSv3.1: 6.5 (MEDIUM)
AV:A/AC:L/Au:N/C:N/I:N/A:P
6.5
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | linux | linux_kernel | ≤ 3.10.108 | Yes |
Operating System | linux | linux_kernel | ≤ 4.18.20 | Yes |
Operating System | debian | debian_linux | 8.0 | Yes |
Operating System | redhat | enterprise_linux | 7.0 | Yes |
Operating System | canonical | ubuntu_linux | 14.04 | Yes |
Operating System | canonical | ubuntu_linux | 16.04 | Yes |
Operating System | canonical | ubuntu_linux | 18.04 | Yes |
Operating System | canonical | ubuntu_linux | 18.10 | Yes |
Operating System | canonical | ubuntu_linux | 19.04 | Yes |
Application | netapp | active_iq_unified_manager_for_vmware_vsphere | ≥ 9.5 | Yes |
Application | netapp | hci_management_node | - | Yes |
Application | netapp | snapprotect | - | Yes |
Application | netapp | solidfire | - | Yes |
Operating System | netapp | cn1610_firmware | - | Yes |
Hardware | netapp | cn1610 | - | No |