CVE-2008-4576
Linux Kernel < 2.6.25.17 - Authentication Bypass
Title source: ruleDescription
sctp in Linux kernel before 2.6.25.18 allows remote attackers to cause a denial of service (OOPS) via an INIT-ACK that states the peer does not support AUTH, which causes the sctp_process_init function to clean up active transports and triggers the OOPS when the T1-Init timer expires.
Scores
EPSS
0.0482
EPSS Percentile
89.3%
Classification
CWE
CWE-287
Status
draft
Affected Products (50)
linux/linux_kernel
< 2.6.25.17
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
... and 35 more
Timeline
Published
Oct 15, 2008
Tracked Since
Feb 18, 2026