CVE-2010-3432

Priority
Medium
Description
The sctp_packet_config function in net/sctp/output.c in the Linux kernel
before 2.6.35.6 performs extraneous initializations of packet data
structures, which allows remote attackers to cause a denial of service
(panic) via a certain sequence of SCTP traffic.
Ubuntu-Description
Thomas Dreibholz discovered that SCTP did not correctly handle appending
packet chunks. A remote attacker could send specially crafted traffic to
crash the system, leading to a denial of service.
References
Bugs
Assigned-to
bradf
Package
Upstream:needs-triage
Ubuntu 8.04 LTS (Hardy Heron):DNE
Ubuntu 10.04 LTS (Lucid Lynx):DNE
Ubuntu 11.04 (Natty Narwhal):DNE
Patches:
Dapper:http://chinstrap.ubuntu.com/~bradf/CVEs/CVE-2010-3432/patches/dapper/linux/0001-sctp-Do-not-reset-the-packet-during-sctp_packet_config.txt
Package
Upstream:needs-triage
Ubuntu 8.04 LTS (Hardy Heron):DNE
Ubuntu 10.04 LTS (Lucid Lynx):released (2.6.32-309.18)
Ubuntu 11.04 (Natty Narwhal):DNE
Package
Upstream:needs-triage
Ubuntu 8.04 LTS (Hardy Heron):DNE
Ubuntu 10.04 LTS (Lucid Lynx):released (2.6.32-216.33)
Ubuntu 11.04 (Natty Narwhal):DNE
Package
Upstream:needs-triage
Ubuntu 8.04 LTS (Hardy Heron):DNE
Ubuntu 10.04 LTS (Lucid Lynx):released (2.6.35-25.44~lucid1)
Ubuntu 11.04 (Natty Narwhal):DNE
Package
Source: linux (LP Ubuntu Debian)
Upstream:needs-triage
Ubuntu 8.04 LTS (Hardy Heron):released (2.6.24-28.80)
Ubuntu 10.04 LTS (Lucid Lynx):released (2.6.32-25.45)
Ubuntu 11.04 (Natty Narwhal):not-affected
Patches:
Upstream:http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=4bdab43323b459900578b200a4b8cf9713ac8fab
Hardy:http://chinstrap.ubuntu.com/~bradf/CVEs/CVE-2010-3432/patches/hardy/linux/0001-sctp-Do-not-reset-the-packet-during-sctp_packet_config.txt
Jaunty:http://chinstrap.ubuntu.com/~bradf/CVEs/CVE-2010-3432/patches/jaunty/linux/0001-sctp-Do-not-reset-the-packet-during-sctp_packet_config.txt
Karmic:http://chinstrap.ubuntu.com/~bradf/CVEs/CVE-2010-3432/patches/karmic/linux/0001-sctp-Do-not-reset-the-packet-during-sctp_packet_config.txt
Lucid:http://chinstrap.ubuntu.com/~bradf/CVEs/CVE-2010-3432/patches/lucid/linux/0001-sctp-Do-not-reset-the-packet-during-sctp_packet_config.txt
Package
Upstream:needs-triage
Ubuntu 8.04 LTS (Hardy Heron):DNE
Ubuntu 10.04 LTS (Lucid Lynx):released (2.6.31-608.22)
Ubuntu 11.04 (Natty Narwhal):DNE
More Information

Valid XHTML 1.0 Strict

Updated: 2012-06-01 15:21:22 UTC (commit 5347)