CVE-2014-3688
Vulnerability Summary
Timeline
Description
The SCTP implementation in the Linux kernel before 3.17.4 allows remote attackers to cause a denial of service (memory consumption) by triggering a large number of chunks in an association's output queue, as demonstrated by ASCONF probes, related to net/sctp/inqueue.c and net/sctp/sm_statefuns.c.
CVSS Metrics
- v2.0•MEDIUM•Score: 5AV:N/AC:L/Au:N/C:N/I:N/A:P
EPSS Trends
Current EPSS score: 1.96%• Percentile: 84%
Techniques & Countermeasures
- CWE-399•Resource Management Errors
Weaknesses in this category are related to improper management of system resources.
Affected Systems
- linux•linux_kernel
≤ 3.17.3 | 3.0:rc1 | 3.0:rc2 | 3.0:rc3 | 3.0:rc4 | 3.0:rc5 | 3.0:rc6 | 3.0:rc7 | 3.0.1 | 3.0.2 | 3.0.3 | 3.0.4 | 3.0.5 | 3.0.6 | 3.0.7 | 3.0.8 | 3.0.9 | 3.0.10 | 3.0.11 | 3.0.12 | 3.0.13 | 3.0.14 | 3.0.15 | 3.0.16 | 3.0.17 | 3.0.18 | 3.0.19 | 3.0.20 | 3.0.21 | 3.0.22 | 3.0.23 | 3.0.24 | 3.0.25 | 3.0.26 | 3.0.27 | 3.0.28 | 3.0.29 | 3.0.30 | 3.0.31 | 3.0.32 | 3.0.33 | 3.0.34 | 3.0.35 | 3.0.36 | 3.0.37 | 3.0.38 | 3.0.39 | 3.0.40 | 3.0.41 | 3.0.42 | 3.0.43 | 3.0.44 | 3.0.45 | 3.0.46 | 3.0.47 | 3.0.48 | 3.0.49 | 3.0.50 | 3.0.51 | 3.0.52 | 3.0.53 | 3.0.54 | 3.0.55 | 3.0.56 | 3.0.57 | 3.0.58 | 3.0.59 | 3.0.60 | 3.0.61 | 3.0.62 | 3.0.63 | 3.0.64 | 3.0.65 | 3.0.66 | 3.0.67 | 3.0.68 | 3.1 | 3.1:rc1 | 3.1:rc2 | 3.1:rc3 | 3.1:rc4 | 3.1.1 | 3.12 | 3.13 | 3.14 | 3.15 | 3.16 | 3.17 | 3.18 | 3.19 | 3.1.10 | 3.2 | 3.2:rc2 | 3.2:rc3 | 3.10 | 3.10.0 | 3.10.1 | 3.10.2 | 3.10.3 | 3.10.4 | 3.10.5 | 3.10.6 | 3.10.7 | 3.10.8 | 3.10.9 | 3.10.10 | 3.10.11 | 3.10.12 | 3.10.13 | 3.10.14 | 3.10.15 | 3.10.16 | 3.10.17 | 3.10.18 | 3.10.19 | 3.10.20 | 3.10.21 | 3.10.22 | 3.10.23 | 3.10.24 | 3.10.25 | 3.10.26 | 3.10.27 | 3.10.28 | 3.10.29 | 3.11.1 | 3.11.2 | 3.11.3 | 3.11.4 | 3.11.5 | 3.11.6 | 3.11.7 | 3.11.8 | 3.11.9 | 3.11.10 | 3.12.1 | 3.12.2 | 3.12.3 | 3.12.4 | 3.12.5 | 3.12.6 | 3.12.7 | 3.12.8 | 3.12.9 | 3.12.10 | 3.12.11 | 3.12.12 | 3.12.13 | 3.12.14 | 3.12.15 | 3.12.16 | 3.12.17 | 3.13.1 | 3.13.2 | 3.13.3 | 3.13.4 | 3.13.5 | 3.13.6 | 3.13.7 | 3.13.8 | 3.13.9 | 3.13.10 | 3.13.11 | 3.14:rc1 | 3.14:rc2 | 3.14:rc3 | 3.14:rc4 | 3.14:rc5 | 3.14:rc6 | 3.14:rc7 | 3.14:rc8 | 3.14.1 | 3.14.2 | 3.14.3 | 3.14.4 | 3.14.5 | 3.15.1 | 3.15.2 | 3.15.3 | 3.15.4 | 3.15.5 | 3.15.6 | 3.15.7 | 3.15.8 | 3.16.0 | 3.16.1 | 3.17.1 | 3.17.2
References (16)
- http://www.openwall.com/lists/oss-security/2014/11/13/8
- http://marc.info/?l=bugtraq&m=142722450701342&w=2
- http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00015.html
- http://www.ubuntu.com/usn/USN-2418-1
- http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00000.html
- http://rhn.redhat.com/errata/RHSA-2015-0062.html
- http://www.ubuntu.com/usn/USN-2417-1
- http://marc.info/?l=bugtraq&m=142722544401658&w=2
- http://www.debian.org/security/2014/dsa-3060
- https://github.com/torvalds/linux/commit/26b87c7881006311828bb0ab271a551a62dcceb4
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=26b87c7881006311828bb0ab271a551a62dcceb4
- http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00010.html
- http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00025.html
- https://bugzilla.redhat.com/show_bug.cgi?id=1155745
- http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.17.4
- http://rhn.redhat.com/errata/RHSA-2015-0115.html