CVE-2006-2274
published 2006-05-09CVE-2006-2274: Linux SCTP (lksctp) before 2.6.17 allows remote attackers to cause a denial of service (infinite recursion and crash) via a packet that contains two or more…
PriorityP421medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
3.82%
89.0th percentile
Linux SCTP (lksctp) before 2.6.17 allows remote attackers to cause a denial of service (infinite recursion and crash) via a packet that contains two or more DATA fragments, which causes an skb pointer to refer back to itself when the full message is reassembled, leading to infinite recursion in the sctp_skb_pull function.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| lksctp | stream_control_transmission_protocol | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_ubuntu6.9MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-p5qf-q563-3822: Linux SCTP (lksctp) before 2
ghsa_unreviewed·2022-05-01
CVE-2006-2274 [MEDIUM] GHSA-p5qf-q563-3822: Linux SCTP (lksctp) before 2
Linux SCTP (lksctp) before 2.6.17 allows remote attackers to cause a denial of service (infinite recursion and crash) via a packet that contains two or more DATA fragments, which causes an skb pointer to refer back to itself when the full message is reassembled, leading to infinite recursion in the sctp_skb_pull function.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2006-06-15·CVSS 6.9
CVE-2006-1856 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Linux kernel vulnerabilities
An integer overflow was discovered in the do_replace() function. A
local user process with the CAP_NET_ADMIN capability could exploit
this to execute arbitrary commands with full root privileges.
However, none of Ubuntu's supported packages use this capability with
any non-root user, so this only affects you if you use some third
party software like the OpenVZ virtualization system. (CVE-2006-0038)
On EMT64 CPUs, the kernel did not properly handle uncanonical return
addresses. A local user could exploit this to trigger a kernel crash.
(CVE-2006-0744)
Al Viro discovered a local Denial of Service in the sysfs write buffer
handling. By writing a block with a length exactly equal to the
processor's page size to any w
Red Hat
security flaw
vendor_redhat·2006-05-09·CVSS 5.0
CVE-2006-2274 [MEDIUM] security flaw
security flaw
Linux SCTP (lksctp) before 2.6.17 allows remote attackers to cause a denial of service (infinite recursion and crash) via a packet that contains two or more DATA fragments, which causes an skb pointer to refer back to itself when the full message is reassembled, leading to infinite recursion in the sctp_skb_pull function.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2006-2274 security flaw
bugzilla·2018-08-16·CVSS 5.0
CVE-2006-2274 [MEDIUM] CVE-2006-2274 security flaw
CVE-2006-2274 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Linux SCTP (lksctp) before 2.6.17 allows remote attackers to cause a denial of service (infinite recursion and crash) via a packet that contains two or more DATA fragments, which causes an skb pointer to refer back to itself when the full message is reassembled, leading to infinite recursion in the sctp_skb_pull function.
Bugzilla
Various kernel security issues - July thru October 2006
bugzilla·2006-07-24·CVSS 4.9
[MEDIUM] Various kernel security issues - July thru October 2006
Various kernel security issues - July thru October 2006
This bug will track the various kernel issues up to July 2006.
Discussion:
*** Bug 188935 has been marked as a duplicate of this bug. ***
---
*** Bug 190082 has been marked as a duplicate of this bug. ***
---
*** Bug 190083 has been marked as a duplicate of this bug. ***
---
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Here are updated kernel packages to QA for FC3:
* Sun Jul 16 2006 Marc Deslauriers
2.6.12-2.4.legacy_FC3
- - Added patches for:
CVE-2005-3359 (incorrect inrement/decrement in atm module)
CVE-2006-0555 (nfs: fix client panic using O_DIRECT)
CVE-2006-0741 (fix for ELF exec vulnerability on EM64T)
CVE-2006-0744 (fix for ELF exec vulnerability on EM64T)
CVE-2006-1525 (panic in ip_route_input() via inet_rtm_getro
Bugzilla
CVE-2006-2274 SCTP DATA fragments DoS
bugzilla·2006-05-10·CVSS 5.0
CVE-2006-2274 [MEDIUM] CVE-2006-2274 SCTP DATA fragments DoS
CVE-2006-2274 SCTP DATA fragments DoS
Linux SCTP before 2.6.17 allows remote attackers to cause a denial of service
via a packet that contains two or more DATA fragments, which causes an skb
pointer to refer back to itself when the full message is reassembled, leading to
infinite recursion in the sctp_skb_pull function.
This issue hasn't been reproduced with RHEL4, but the vulnerable code is the
same as upstream.
The upstream fix can be found here:
http://git.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=672e7cca17ed6036a1756ed34cf20dbd72d5e5f6
Discussion:
committed in stream U4 build 36.1. A test kernel with this patch is available
from http://people.redhat.com/~jbaron/rhel4/
---
An advisory has been issued which should help the problem
described in this bug
http://git.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=672e7cca17ed6036a1756ed34cf20dbd72d5e5f6http://secunia.com/advisories/20237http://secunia.com/advisories/20398http://secunia.com/advisories/20671http://secunia.com/advisories/20716http://secunia.com/advisories/20914http://secunia.com/advisories/21045http://secunia.com/advisories/21476http://secunia.com/advisories/21745http://support.avaya.com/elmodocs2/security/ASA-2006-161.htmhttp://www.debian.org/security/2006/dsa-1097http://www.debian.org/security/2006/dsa-1103http://www.mandriva.com/security/advisories?name=MDKSA-2006:123http://www.mandriva.com/security/advisories?name=MDKSA-2006:150http://www.novell.com/linux/security/advisories/2006-05-31.htmlhttp://www.osvdb.org/25746http://www.redhat.com/support/errata/RHSA-2006-0493.htmlhttp://www.securityfocus.com/bid/17955http://www.trustix.org/errata/2006/0026http://www.ubuntu.com/usn/usn-302-1http://www.vupen.com/english/advisories/2006/2554https://exchange.xforce.ibmcloud.com/vulnerabilities/26432https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9531http://git.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=672e7cca17ed6036a1756ed34cf20dbd72d5e5f6http://secunia.com/advisories/20237http://secunia.com/advisories/20398http://secunia.com/advisories/20671http://secunia.com/advisories/20716http://secunia.com/advisories/20914http://secunia.com/advisories/21045http://secunia.com/advisories/21476http://secunia.com/advisories/21745http://support.avaya.com/elmodocs2/security/ASA-2006-161.htmhttp://www.debian.org/security/2006/dsa-1097http://www.debian.org/security/2006/dsa-1103http://www.mandriva.com/security/advisories?name=MDKSA-2006:123http://www.mandriva.com/security/advisories?name=MDKSA-2006:150http://www.novell.com/linux/security/advisories/2006-05-31.htmlhttp://www.osvdb.org/25746http://www.redhat.com/support/errata/RHSA-2006-0493.htmlhttp://www.securityfocus.com/bid/17955http://www.trustix.org/errata/2006/0026http://www.ubuntu.com/usn/usn-302-1http://www.vupen.com/english/advisories/2006/2554https://exchange.xforce.ibmcloud.com/vulnerabilities/26432https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9531
2006-05-09
Published