The sctp_sf_do_5_1D_ce function in net/sctp/sm_statefuns.c in the Linux kernel through 3.13.6 does not validate certain auth_enable and auth_capable fields before making an sctp_sf_authenticate call, which allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) via an SCTP handshake with a modified INIT chunk and a crafted AUTH chunk before a COOKIE_ECHO chunk.

Project Subscriptions

Vendors Products
Canonical Subscribe
Ubuntu Linux Subscribe
Big-ip Access Policy Manager Subscribe
Big-ip Advanced Firewall Manager Subscribe
Big-ip Analytics Subscribe
Big-ip Application Acceleration Manager Subscribe
Big-ip Application Security Manager Subscribe
Big-ip Edge Gateway Subscribe
Big-ip Enterprise Manager Subscribe
Big-ip Global Traffic Manager Subscribe
Big-ip Link Controller Subscribe
Big-ip Local Traffic Manager Subscribe
Big-ip Policy Enforcement Manager Subscribe
Big-ip Protocol Security Module Subscribe
Big-ip Wan Optimization Manager Subscribe
Big-ip Webaccelerator Subscribe
Big-iq Adc Subscribe
Big-iq Centralized Management Subscribe
Big-iq Cloud Subscribe
Big-iq Device Subscribe
Big-iq Security Subscribe
Linux Kernel Subscribe
Enterprise Linux Subscribe
Enterprise Linux Desktop Subscribe
Enterprise Linux Eus Subscribe
Enterprise Linux Server Subscribe
Enterprise Linux Server Aus Subscribe
Enterprise Linux Server Tus Subscribe
Enterprise Linux Workstation Subscribe
Rhel Eus Subscribe
Rhel Mission Critical Subscribe
Advisories
Source ID Title
Debian DSA Debian DSA DSA-2906-1 linux-2.6 security update
EUVD EUVD EUVD-2014-0181 The sctp_sf_do_5_1D_ce function in net/sctp/sm_statefuns.c in the Linux kernel through 3.13.6 does not validate certain auth_enable and auth_capable fields before making an sctp_sf_authenticate call, which allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) via an SCTP handshake with a modified INIT chunk and a crafted AUTH chunk before a COOKIE_ECHO chunk.
Ubuntu USN Ubuntu USN USN-2173-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-2174-1 Linux kernel (EC2) vulnerabilities
Ubuntu USN Ubuntu USN USN-2221-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-2223-1 Linux kernel (Quantal HWE) vulnerabilities
Ubuntu USN Ubuntu USN USN-2224-1 Linux kernel (Raring HWE) vulnerabilities
Ubuntu USN Ubuntu USN USN-2225-1 Linux kernel (Saucy HWE) vulnerabilities
Ubuntu USN Ubuntu USN USN-2227-1 Linux kernel (OMAP4) vulnerabilities
Ubuntu USN Ubuntu USN USN-2228-1 Linux kernel vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-06T09:05:38.283Z

Reserved: 2013-12-03T00:00:00

Link: CVE-2014-0101

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2014-03-11T13:01:06.733

Modified: 2025-04-12T10:46:40.837

Link: CVE-2014-0101

cve-icon Redhat

Severity : Important

Publid Date: 2014-03-03T00:00:00Z

Links: CVE-2014-0101 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses