The SCTP implementation in the Linux kernel before 3.17.4 allows remote attackers to cause a denial of service (memory consumption) by triggering a large number of chunks in an association's output queue, as demonstrated by ASCONF probes, related to net/sctp/inqueue.c and net/sctp/sm_statefuns.c.
Metrics
No CVSS v4.0
No CVSS v3.1
No CVSS v3.0
Access Vector Network
Access Complexity Low
Authentication None
Confidentiality Impact None
Integrity Impact None
Availability Impact Partial
AV:N/AC:L/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
Key SSVC decision points have not yet been added.
Affected Vendors & Products
Vendors | Products |
---|---|
Linux |
|
Redhat |
|
Configuration 1 [-]
|
Package | CPE | Advisory | Released Date |
---|---|---|---|
Red Hat Enterprise Linux 6 | |||
kernel-0:2.6.32-504.3.3.el6 | cpe:/o:redhat:enterprise_linux:6 | RHSA-2014:1997 | 2014-12-16T00:00:00Z |
Red Hat Enterprise Linux 6.2 Advanced Update Support | |||
kernel-0:2.6.32-220.58.1.el6 | cpe:/o:redhat:rhel_mission_critical:6.2 | RHSA-2015:0115 | 2015-02-03T00:00:00Z |
Red Hat Enterprise Linux 6.4 Extended Update Support | |||
kernel-0:2.6.32-358.55.1.el6 | cpe:/o:redhat:rhel_eus:6.4 | RHSA-2015:0043 | 2015-01-13T00:00:00Z |
Red Hat Enterprise Linux 6.5 Extended Update Support | |||
kernel-0:2.6.32-431.46.2.el6 | cpe:/o:redhat:rhel_eus:6.5 | RHSA-2015:0062 | 2015-01-20T00:00:00Z |
Red Hat Enterprise Linux 7 | |||
kernel-0:3.10.0-123.13.1.el7 | cpe:/o:redhat:enterprise_linux:7 | RHSA-2014:1971 | 2014-12-09T00:00:00Z |
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: redhat
Published: 2014-11-30T01:00:00
Updated: 2024-08-06T10:50:18.333Z
Reserved: 2014-05-14T00:00:00
Link: CVE-2014-3688
Vulnrichment
No data.
NVD
Status : Modified
Published: 2014-11-30T01:59:02.307
Modified: 2024-11-21T02:08:39.293
Link: CVE-2014-3688
Redhat