CVE-2008-4113
Linux Kernel < 2.6.25.14 - Information Disclosure
Title source: ruleDescription
The sctp_getsockopt_hmac_ident function in net/sctp/socket.c in the Stream Control Transmission Protocol (sctp) implementation in the Linux kernel before 2.6.26.4, when the SCTP-AUTH extension is enabled, relies on an untrusted length value to limit copying of data from kernel memory, which allows local users to obtain sensitive information via a crafted SCTP_HMAC_IDENT IOCTL request involving the sctp_getsockopt function.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Jon Oberheide · clocallinux
https://www.exploit-db.com/exploits/7618
References (17)
Scores
EPSS
0.0019
EPSS Percentile
40.6%
Classification
CWE
CWE-200
Status
draft
Affected Products (50)
linux/linux_kernel
< 2.6.25.14
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
... and 35 more
Timeline
Published
Sep 16, 2008
Tracked Since
Feb 18, 2026