A flaw was found in the sctp_make_strreset_req function in net/sctp/sm_make_chunk.c in the SCTP network protocol in the Linux kernel with a local user privilege access. In this flaw, an attempt to use more buffer than is allocated triggers a BUG_ON issue, leading to a denial of service (DOS).
2022-03-25T19:15:09.967
2024-11-21T06:38:22.593
Modified
CVSSv3.1: 5.5 (MEDIUM)
AV:L/AC:L/Au:N/C:N/I:N/A:P
3.9
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | linux | linux_kernel | < 5.15 | Yes |
| Operating System | linux | linux_kernel | 5.15 | Yes |
| Operating System | linux | linux_kernel | 5.15 | Yes |
| Operating System | linux | linux_kernel | 5.15 | Yes |
| Operating System | linux | linux_kernel | 5.15 | Yes |
| Operating System | linux | linux_kernel | 5.15 | Yes |
| Operating System | linux | linux_kernel | 5.15 | Yes |
| Operating System | fedoraproject | fedora | 35 | Yes |
| Application | oracle | communications_cloud_native_core_binding_support_function | 22.1.3 | Yes |
| Application | oracle | communications_cloud_native_core_network_exposure_function | 22.1.1 | Yes |
| Application | oracle | communications_cloud_native_core_policy | 22.2.0 | Yes |