CVE-2008-3792

Linux Kernel < 2.6.26.4 - Denial of Service via SCTP-AUTH API Functions

Title source: llm
STIX 2.1

Description

net/sctp/socket.c in the Stream Control Transmission Protocol (sctp) implementation in the Linux kernel before 2.6.26.4 does not verify that the SCTP-AUTH extension is enabled before proceeding with SCTP-AUTH API functions, which allows attackers to cause a denial of service (NULL pointer dereference and panic) via vectors that result in calls to (1) sctp_setsockopt_auth_chunk, (2) sctp_setsockopt_hmac_ident, (3) sctp_setsockopt_auth_key, (4) sctp_setsockopt_active_key, (5) sctp_setsockopt_del_key, (6) sctp_getsockopt_maxburst, (7) sctp_getsockopt_active_key, (8) sctp_getsockopt_peer_auth_chunks, or (9) sctp_getsockopt_local_auth_chunks.

References (21)

Core 21
Core References
Various Sources x_refsource_misc
http://www.trapkit.de/advisories/TKADV2008-007.txt
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/32190
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/32393
Patch vendor-advisory x_refsource_debian
http://www.debian.org/security/2008/dsa-1636
Exploit, Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/31121
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2008/08/26/8
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2008/08/26/6
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/31881
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/usn-659-1
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/45189
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2008-0857.html
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2008/08/25/1
Various Sources mailing-list x_refsource_mlist
http://lkml.org/lkml/2008/8/23/49
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1020854
Exploit third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/4210
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/496256/100/0/threaded
Mailing List mailing-list x_refsource_mlist
http://marc.info/?l=linux-netdev&m=121928747903176&w=2
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2008/09/26/6

Scores

EPSS 0.0267
EPSS Percentile 84.3%

Details

Status published
Products (1)
linux/linux_kernel 2.6.26.3
Published Sep 03, 2008
Tracked Since Feb 18, 2026