CVE-2010-3705 (retired)

Priority
Description
The sctp_auth_asoc_get_hmac function in net/sctp/auth.c in the Linux kernel
before 2.6.36 does not properly validate the hmac_ids array of an SCTP
peer, which allows remote attackers to cause a denial of service (memory
corruption and panic) via a crafted value in the last element of this
array.
Ubuntu-Description
Dan Rosenberg discovered that SCTP did not correctly handle HMAC
calculations. A remote attacker could send specially crafted traffic that
would crash the system, leading to a denial of service.
Assigned-to
smb
Package
Upstream:needs-triage
Package
Upstream:needs-triage
Package
Upstream:needs-triage
Package
Upstream:needs-triage
Package
Upstream:not-affected
Package
Upstream:needs-triage
More Information

Updated: 2019-03-26 11:53:27 UTC (commit ccdecfcf0fead22bd291e5f4ea745a46872dcb15)