CVE-2015-1421

CVSS v2.0 10 (High)
100% Progress
EPSS 5.79 % (94th)
5.79% Progress
Affected Products 3
Advisories 35

Use-after-free vulnerability in the sctp_assoc_update function in net/sctp/associola.c in the Linux kernel before 3.18.8 allows remote attackers to cause a denial of service (slab corruption and panic) or possibly have unspecified other impact by triggering an INIT collision that leads to improper handling of shared-key data.

Weaknesses
CWE-NVD-Other
CVE Status
PUBLISHED
CNA
MITRE
Published Date
2015-03-16 10:59:06
(9 years ago)
Updated Date
2023-11-07 02:24:49
(10 months ago)

Affected Products

Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Linux Kernel from 2.6.24 version and prior 3.2.67 version cpe:2.3:o:linux:linux_kernel >= 2.6.24 < 3.2.67
  Linux Kernel from 3.3 version and prior 3.4.107 version cpe:2.3:o:linux:linux_kernel >= 3.3 < 3.4.107
  Linux Kernel from 3.5 version and prior 3.10.70 version cpe:2.3:o:linux:linux_kernel >= 3.5 < 3.10.70
  Linux Kernel from 3.11 version and prior 3.12.38 version cpe:2.3:o:linux:linux_kernel >= 3.11 < 3.12.38
  Linux Kernel from 3.13 version and prior 3.14.34 version cpe:2.3:o:linux:linux_kernel >= 3.13 < 3.14.34
  Linux Kernel from 3.15 version and prior 3.16.35 version cpe:2.3:o:linux:linux_kernel >= 3.15 < 3.16.35
  Linux Kernel from 3.17 version and prior 3.18.8 version cpe:2.3:o:linux:linux_kernel >= 3.17 < 3.18.8

Configuration #2

    CPE23 From Up To
  Canonical Ubuntu Linux 12.04 cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:-
  Canonical Ubuntu Linux 14.04 cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm
  Canonical Ubuntu Linux 14.10 cpe:2.3:o:canonical:ubuntu_linux:14.10

Configuration #3

    CPE23 From Up To
  Debian Linux 7.0 cpe:2.3:o:debian:debian_linux:7.0
  Debian Linux 8.0 cpe:2.3:o:debian:debian_linux:8.0
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...