The ECNE chunk handling in Linux SCTP (lksctp) before 2.6.17 allows remote attackers to cause a denial of service (kernel panic) via an unexpected chunk when the session is in CLOSED state.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Lksctp | Lksctp | 2.6.0_test1_0.7.2 (including) | 2.6.0_test1_0.7.2 (including) |
Lksctp | Lksctp | 2.6.0_test4_0.7.3 (including) | 2.6.0_test4_0.7.3 (including) |
Lksctp | Lksctp | 2.6.2_0.9.0 (including) | 2.6.2_0.9.0 (including) |
Lksctp | Lksctp | 2.6.3_1.0.0 (including) | 2.6.3_1.0.0 (including) |
Lksctp | Lksctp | 2.6.6_1.0.1 (including) | 2.6.6_1.0.1 (including) |
Lksctp | Lksctp | 2.6.10_1.0.2 (including) | 2.6.10_1.0.2 (including) |
Lksctp | Lksctp | 2.6.13_1.0.3 (including) | 2.6.13_1.0.3 (including) |
Lksctp | Lksctp | 2.6.14_1.0.4 (including) | 2.6.14_1.0.4 (including) |
Lksctp | Lksctp | 2.6.15_1.0.5 (including) | 2.6.15_1.0.5 (including) |
Lksctp | Lksctp | 2.6.16_1.0.6 (including) | 2.6.16_1.0.6 (including) |
Red Hat Enterprise Linux 4 | RedHat | kernel-0:2.6.9-34.0.1.EL | * |
Linux-source-2.6.15 | Ubuntu | dapper | * |
Linux-source-2.6.17 | Ubuntu | edgy | * |