CVE-2008-2826
published 2008-07-02CVE-2008-2826: Integer overflow in the sctp_getsockopt_local_addrs_old function in net/sctp/socket.c in the Stream Control Transmission Protocol (sctp) functionality in the…
PriorityP414medium4.9CVSS 2.0
AVLACLAuNCNINAC
EPSS
0.43%
35.3th percentile
Integer overflow in the sctp_getsockopt_local_addrs_old function in net/sctp/socket.c in the Stream Control Transmission Protocol (sctp) functionality in the Linux kernel before 2.6.25.9 allows local users to cause a denial of service (resource consumption and system outage) via vectors involving a large addr_num field in an sctp_getaddrs_old data structure.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| linux | linux_kernel | < 2.6.25.9 | 2.6.25.9 |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
CVSS provenance
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
vendor_ubuntu7.1HIGH
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2008-07-15·CVSS 7.1
CVE-2008-2826 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Linux kernel vulnerabilities
Dirk Nehring discovered that the IPsec protocol stack did not correctly
handle fragmented ESP packets. A remote attacker could exploit this to
crash the system, leading to a denial of service. (CVE-2007-6282)
Johannes Bauer discovered that the 64bit kernel did not correctly handle
hrtimer updates. A local attacker could request a large expiration value
and cause the system to hang, leading to a denial of service.
(CVE-2007-6712)
Tavis Ormandy discovered that the ia32 emulation under 64bit kernels did
not fully clear uninitialized data. A local attacker could read private
kernel memory, leading to a loss of privacy. (CVE-2008-0598)
Jan Kratochvil discovered that PTRACE did not correctly handle certain
calls when
Red Hat
kernel: sctp: sctp_getsockopt_local_addrs_old() potential overflow
vendor_redhat·2008-06-21·CVSS 4.9
CVE-2008-2826 [MEDIUM] kernel: sctp: sctp_getsockopt_local_addrs_old() potential overflow
kernel: sctp: sctp_getsockopt_local_addrs_old() potential overflow
Integer overflow in the sctp_getsockopt_local_addrs_old function in net/sctp/socket.c in the Stream Control Transmission Protocol (sctp) functionality in the Linux kernel before 2.6.25.9 allows local users to cause a denial of service (resource consumption and system outage) via vectors involving a large addr_num field in an sctp_getaddrs_old data structure.
GHSA
GHSA-m6m3-cpjp-mwgw: Integer overflow in the sctp_getsockopt_local_addrs_old function in net/sctp/socket
ghsa_unreviewed·2022-05-01
CVE-2008-2826 [MEDIUM] CWE-190 GHSA-m6m3-cpjp-mwgw: Integer overflow in the sctp_getsockopt_local_addrs_old function in net/sctp/socket
Integer overflow in the sctp_getsockopt_local_addrs_old function in net/sctp/socket.c in the Stream Control Transmission Protocol (sctp) functionality in the Linux kernel before 2.6.25.9 allows local users to cause a denial of service (resource consumption and system outage) via vectors involving a large addr_num field in an sctp_getaddrs_old data structure.
No detection rules found.
No public exploits indexed.
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=735ce972fbc8a65fb17788debd7bbe7b4383cc62http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.25.9http://lists.opensuse.org/opensuse-security-announce/2008-07/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-10/msg00008.htmlhttp://lwn.net/Articles/287350/http://secunia.com/advisories/30901http://secunia.com/advisories/31107http://secunia.com/advisories/31202http://secunia.com/advisories/31551http://secunia.com/advisories/31628http://secunia.com/advisories/32370http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0207http://www.debian.org/security/2008/dsa-1630http://www.kernel.org/pub/linux/kernel/v2.4/ChangeLog-2.4.36.7http://www.mandriva.com/security/advisories?name=MDVSA-2008:167http://www.mandriva.com/security/advisories?name=MDVSA-2008:174http://www.redhat.com/support/errata/RHSA-2008-0585.htmlhttp://www.securityfocus.com/bid/29990http://www.securitytracker.com/id?1020514http://www.ubuntu.com/usn/usn-625-1http://www.vupen.com/english/advisories/2008/2511https://exchange.xforce.ibmcloud.com/vulnerabilities/43559https://issues.rpath.com/browse/RPL-2629http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=735ce972fbc8a65fb17788debd7bbe7b4383cc62http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.25.9http://lists.opensuse.org/opensuse-security-announce/2008-07/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-10/msg00008.htmlhttp://lwn.net/Articles/287350/http://secunia.com/advisories/30901http://secunia.com/advisories/31107http://secunia.com/advisories/31202http://secunia.com/advisories/31551http://secunia.com/advisories/31628http://secunia.com/advisories/32370http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0207http://www.debian.org/security/2008/dsa-1630http://www.kernel.org/pub/linux/kernel/v2.4/ChangeLog-2.4.36.7http://www.mandriva.com/security/advisories?name=MDVSA-2008:167http://www.mandriva.com/security/advisories?name=MDVSA-2008:174http://www.redhat.com/support/errata/RHSA-2008-0585.htmlhttp://www.securityfocus.com/bid/29990http://www.securitytracker.com/id?1020514http://www.ubuntu.com/usn/usn-625-1http://www.vupen.com/english/advisories/2008/2511https://exchange.xforce.ibmcloud.com/vulnerabilities/43559https://issues.rpath.com/browse/RPL-2629
2008-07-02
Published