The SCTP implementation in the Linux kernel before 3.17.4 allows remote attackers to cause a denial of service (memory consumption) by triggering a large number of chunks in an association's output queue, as demonstrated by ASCONF probes, related to net/sctp/inqueue.c and net/sctp/sm_statefuns.c.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-118-1 | linux-2.6 security update |
Debian DSA |
DSA-3060-1 | linux security update |
EUVD |
EUVD-2014-3634 | The SCTP implementation in the Linux kernel before 3.17.4 allows remote attackers to cause a denial of service (memory consumption) by triggering a large number of chunks in an association's output queue, as demonstrated by ASCONF probes, related to net/sctp/inqueue.c and net/sctp/sm_statefuns.c. |
Ubuntu USN |
USN-2417-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-2418-1 | Linux kernel (OMAP4) vulnerabilities |
Ubuntu USN |
USN-2441-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-2442-1 | Linux kernel (EC2) vulnerabilities |
Ubuntu USN |
USN-2445-1 | Linux kernel (Trusty HWE) vulnerabilities |
Ubuntu USN |
USN-2446-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-2447-1 | Linux kernel (Utopic HWE) vulnerabilities |
Ubuntu USN |
USN-2448-1 | Linux kernel vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T10:50:18.333Z
Reserved: 2014-05-14T00:00:00
Link: CVE-2014-3688
No data.
Status : Deferred
Published: 2014-11-30T01:59:02.307
Modified: 2025-04-12T10:46:40.837
Link: CVE-2014-3688
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Ubuntu USN