CVE-2010-3432

CVSS v2.0 7.8 (High)
78% Progress
EPSS 1.71 % (88th)
1.71% Progress
Affected Products 5
Advisories 13

The sctp_packet_config function in net/sctp/output.c in the Linux kernel before 2.6.35.6 performs extraneous initializations of packet data structures, which allows remote attackers to cause a denial of service (panic) via a certain sequence of SCTP traffic.

Weaknesses
CWE-20
Improper Input Validation
CVE Status
PUBLISHED
CNA
Red Hat, Inc.
Published Date
2010-11-22 13:00:02
(14 years ago)
Updated Date
2023-02-13 04:24:32
(19 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Linux Kernel prior 2.6.35.6 version cpe:2.3:o:linux:linux_kernel < 2.6.35.6

Configuration #2

    CPE23 From Up To
  Opensuse 11.3 cpe:2.3:o:opensuse:opensuse:11.3
  Suse Linux Enterprise Real Time Extension 11 SP1 cpe:2.3:o:suse:linux_enterprise_real_time_extension:11:sp1

Configuration #3

    CPE23 From Up To
  Debian Linux 5.0 cpe:2.3:o:debian:debian_linux:5.0

Configuration #4

    CPE23 From Up To
  Canonical Ubuntu Linux 6.06 cpe:2.3:o:canonical:ubuntu_linux:6.06
  Canonical Ubuntu Linux 8.04 cpe:2.3:o:canonical:ubuntu_linux:8.04:*:*:*:-
  Canonical Ubuntu Linux 9.04 cpe:2.3:o:canonical:ubuntu_linux:9.04
  Canonical Ubuntu Linux 9.10 cpe:2.3:o:canonical:ubuntu_linux:9.10
  Canonical Ubuntu Linux 10.04 cpe:2.3:o:canonical:ubuntu_linux:10.04:*:*:*:-
  Canonical Ubuntu Linux 10.10 cpe:2.3:o:canonical:ubuntu_linux:10.10
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...