CVE-2006-1857
published 2006-05-22CVE-2006-1857: Buffer overflow in SCTP in Linux kernel before 2.6.16.17 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a…
PriorityP341critical9CVSS 2.0
AVNACLAuNCPIPAC
EPSS
6.80%
93.3th percentile
Buffer overflow in SCTP in Linux kernel before 2.6.16.17 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a malformed HB-ACK chunk.
Affected
60 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
CVSS provenance
nvdv2.09.0CRITICALAV:N/AC:L/Au:N/C:P/I:P/A:C
vendor_redhat9.0CRITICAL
vendor_ubuntu6.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2006-06-15·CVSS 6.9
CVE-2006-1856 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Linux kernel vulnerabilities
An integer overflow was discovered in the do_replace() function. A
local user process with the CAP_NET_ADMIN capability could exploit
this to execute arbitrary commands with full root privileges.
However, none of Ubuntu's supported packages use this capability with
any non-root user, so this only affects you if you use some third
party software like the OpenVZ virtualization system. (CVE-2006-0038)
On EMT64 CPUs, the kernel did not properly handle uncanonical return
addresses. A local user could exploit this to trigger a kernel crash.
(CVE-2006-0744)
Al Viro discovered a local Denial of Service in the sysfs write buffer
handling. By writing a block with a length exactly equal to the
processor's page size to any w
Red Hat
security flaw
vendor_redhat·2006-05-19·CVSS 9.0
CVE-2006-1857 [CRITICAL] security flaw
security flaw
Buffer overflow in SCTP in Linux kernel before 2.6.16.17 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a malformed HB-ACK chunk.
GHSA
GHSA-96q8-85wv-4x4w: Buffer overflow in SCTP in Linux kernel before 2
ghsa_unreviewed·2022-05-01
CVE-2006-1857 [HIGH] CWE-119 GHSA-96q8-85wv-4x4w: Buffer overflow in SCTP in Linux kernel before 2
Buffer overflow in SCTP in Linux kernel before 2.6.16.17 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a malformed HB-ACK chunk.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2006-1857 security flaw
bugzilla·2018-08-16·CVSS 9.0
CVE-2006-1857 [CRITICAL] CVE-2006-1857 security flaw
CVE-2006-1857 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Buffer overflow in SCTP in Linux kernel before 2.6.16.17 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a malformed HB-ACK chunk.
Bugzilla
Various kernel security issues - July thru October 2006
bugzilla·2006-07-24·CVSS 4.9
[MEDIUM] Various kernel security issues - July thru October 2006
Various kernel security issues - July thru October 2006
This bug will track the various kernel issues up to July 2006.
Discussion:
*** Bug 188935 has been marked as a duplicate of this bug. ***
---
*** Bug 190082 has been marked as a duplicate of this bug. ***
---
*** Bug 190083 has been marked as a duplicate of this bug. ***
---
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Here are updated kernel packages to QA for FC3:
* Sun Jul 16 2006 Marc Deslauriers
2.6.12-2.4.legacy_FC3
- - Added patches for:
CVE-2005-3359 (incorrect inrement/decrement in atm module)
CVE-2006-0555 (nfs: fix client panic using O_DIRECT)
CVE-2006-0741 (fix for ELF exec vulnerability on EM64T)
CVE-2006-0744 (fix for ELF exec vulnerability on EM64T)
CVE-2006-1525 (panic in ip_route_input() via inet_rtm_getro
Bugzilla
CVE-2006-1857 SCTP HB-ACK chunk overflow
bugzilla·2006-05-22·CVSS 9.0
CVE-2006-1857 [CRITICAL] CVE-2006-1857 SCTP HB-ACK chunk overflow
CVE-2006-1857 SCTP HB-ACK chunk overflow
If SCTP receives a badly formatted HB-ACK chunk, it is possible that we may
access invalid memory and potentially have a buffer overflow.
The upstream fix can be found here:
http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=dd2d1c6f2958d027e4591ca5d2a04dfe36ca6512
Discussion:
This is the link for the real upstream fix:
http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=a601266e4f3c479790f373c2e3122a766d123652
---
committed in stream U4 build 39.1. A test kernel with this patch is available
from http://people.redhat.com/~jbaron/rhel4/
---
Patch is in -42.EL.
---
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
c
http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.17http://secunia.com/advisories/20185http://secunia.com/advisories/20671http://secunia.com/advisories/20716http://secunia.com/advisories/20914http://secunia.com/advisories/21045http://secunia.com/advisories/21179http://secunia.com/advisories/21465http://secunia.com/advisories/21476http://secunia.com/advisories/21498http://secunia.com/advisories/22417http://support.avaya.com/elmodocs2/security/ASA-2006-200.htmhttp://www.debian.org/security/2006/dsa-1097http://www.debian.org/security/2006/dsa-1103http://www.mandriva.com/security/advisories?name=MDKSA-2006:123http://www.mandriva.com/security/advisories?name=MDKSA-2006:150http://www.novell.com/linux/security/advisories/2006_42_kernel.htmlhttp://www.novell.com/linux/security/advisories/2006_47_kernel.htmlhttp://www.osvdb.org/25695http://www.redhat.com/support/errata/RHSA-2006-0575.htmlhttp://www.securityfocus.com/bid/18085http://www.ubuntu.com/usn/usn-302-1http://www.vupen.com/english/advisories/2006/1893http://www.vupen.com/english/advisories/2006/2554https://exchange.xforce.ibmcloud.com/vulnerabilities/26584https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10622http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.17http://secunia.com/advisories/20185http://secunia.com/advisories/20671http://secunia.com/advisories/20716http://secunia.com/advisories/20914http://secunia.com/advisories/21045http://secunia.com/advisories/21179http://secunia.com/advisories/21465http://secunia.com/advisories/21476http://secunia.com/advisories/21498http://secunia.com/advisories/22417http://support.avaya.com/elmodocs2/security/ASA-2006-200.htmhttp://www.debian.org/security/2006/dsa-1097http://www.debian.org/security/2006/dsa-1103http://www.mandriva.com/security/advisories?name=MDKSA-2006:123http://www.mandriva.com/security/advisories?name=MDKSA-2006:150http://www.novell.com/linux/security/advisories/2006_42_kernel.htmlhttp://www.novell.com/linux/security/advisories/2006_47_kernel.htmlhttp://www.osvdb.org/25695http://www.redhat.com/support/errata/RHSA-2006-0575.htmlhttp://www.securityfocus.com/bid/18085http://www.ubuntu.com/usn/usn-302-1http://www.vupen.com/english/advisories/2006/1893http://www.vupen.com/english/advisories/2006/2554https://exchange.xforce.ibmcloud.com/vulnerabilities/26584https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10622
2006-05-22
Published