Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-8767

Опубликовано: 11 янв. 2015
Источник: redhat
CVSS2: 7.1
EPSS Низкий

Описание

net/sctp/sm_sideeffect.c in the Linux kernel before 4.3 does not properly manage the relationship between a lock and a socket, which allows local users to cause a denial of service (deadlock) via a crafted sctp_accept call.

A race condition flaw was found in the way the Linux kernel's SCTP implementation handled sctp_accept() during the processing of heartbeat timeout events. A remote attacker could use this flaw to prevent further connections to be accepted by the SCTP server running on the system, resulting in a denial of service.

Отчет

This issue affects the Linux kernel packages as shipped with Red Hat Enterprise Linux 6, 7 and MRG-2 and may be addressed in future updates. This issue affects the Linux kernel packages as shipped with Red Hat Enterprise Linux 5. Red Hat Enterprise Linux 5 is now in Production 3 Phase of the support and maintenance life cycle. This has been rated as having Moderate security impact and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5kernelWill not fix
Red Hat Enterprise Linux Extended Update Support 6.6kernelAffected
Red Hat Enterprise Linux 6kernelFixedRHSA-2016:071504.05.2016
Red Hat Enterprise Linux 7kernel-rtFixedRHSA-2016:130123.06.2016
Red Hat Enterprise Linux 7kernelFixedRHSA-2016:127723.06.2016
Red Hat Enterprise MRG 2kernel-rtFixedRHSA-2016:134127.06.2016

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-367
https://bugzilla.redhat.com/show_bug.cgi?id=1297389kernel: SCTP denial of service during timeout

EPSS

Процентиль: 32%
0.00121
Низкий

7.1 High

CVSS2

Связанные уязвимости

CVSS3: 6.2
ubuntu
больше 9 лет назад

net/sctp/sm_sideeffect.c in the Linux kernel before 4.3 does not properly manage the relationship between a lock and a socket, which allows local users to cause a denial of service (deadlock) via a crafted sctp_accept call.

CVSS3: 6.2
nvd
больше 9 лет назад

net/sctp/sm_sideeffect.c in the Linux kernel before 4.3 does not properly manage the relationship between a lock and a socket, which allows local users to cause a denial of service (deadlock) via a crafted sctp_accept call.

CVSS3: 6.2
debian
больше 9 лет назад

net/sctp/sm_sideeffect.c in the Linux kernel before 4.3 does not prope ...

CVSS3: 6.2
github
около 3 лет назад

net/sctp/sm_sideeffect.c in the Linux kernel before 4.3 does not properly manage the relationship between a lock and a socket, which allows local users to cause a denial of service (deadlock) via a crafted sctp_accept call.

oracle-oval
около 9 лет назад

ELSA-2016-3554: Unbreakable Enterprise kernel security update (MODERATE)

EPSS

Процентиль: 32%
0.00121
Низкий

7.1 High

CVSS2