CVE-2013-2206
published 2013-07-04CVE-2013-2206: The sctp_sf_do_5_2_4_dupcook function in net/sctp/sm_statefuns.c in the SCTP implementation in the Linux kernel before 3.8.5 does not properly handle…
PriorityP428medium5.4CVSS 2.0
AVNACHAuNCNINAC
EPSS
4.71%
90.9th percentile
The sctp_sf_do_5_2_4_dupcook function in net/sctp/sm_statefuns.c in the SCTP implementation in the Linux kernel before 3.8.5 does not properly handle associations during the processing of a duplicate COOKIE ECHO chunk, which allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via crafted SCTP traffic.
Affected
193 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.9.4-1 (bookworm) | linux 3.9.4-1 (bookworm) |
| linux | linux_kernel | <= 3.8.4 | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
CVSS provenance
nvdv2.05.4MEDIUMAV:N/AC:H/Au:N/C:N/I:N/A:C
osv5.4MEDIUM
vendor_ubuntu6.9MEDIUM
vendor_debian5.4MEDIUM
vendor_redhat5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2013-09-06·CVSS 6.9
CVE-2013-1060 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Vasily Kulikov discovered a flaw in the Linux Kernel's perf tool that
allows for privilege escalation. A local user could exploit this flaw to
run commands as root when using the perf tool.
(CVE-2013-1060)
Michael S. Tsirkin discovered a flaw in how the Linux kernel's KVM
subsystem allocates memory slots for the guest's address space. A local
user could exploit this flaw to gain system privileges or obtain sensitive
information from kernel memory. (CVE-2013-1943)
A flaw was discovered in the SCTP (stream control transfer protocol)
network protocol's handling of duplicate cookies in the Linux kernel. A
remote attacker could exploit this flaw to cause a denial of service
(system crash) on anoth
Ubuntu
Linux kernel (EC2) vulnerabilities
vendor_ubuntu·2013-09-06·CVSS 6.9
CVE-2013-1060 [MEDIUM] Linux kernel (EC2) vulnerabilities
Title: Linux kernel (EC2) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Vasily Kulikov discovered a flaw in the Linux Kernel's perf tool that
allows for privilege escalation. A local user could exploit this flaw to
run commands as root when using the perf tool. (CVE-2013-1060)
Michael S. Tsirkin discovered a flaw in how the Linux kernel's KVM
subsystem allocates memory slots for the guest's address space. A local
user could exploit this flaw to gain system privileges or obtain sensitive
information from kernel memory. (CVE-2013-1943)
A flaw was discovered in the SCTP (stream control transfer protocol)
network protocol's handling of duplicate cookies in the Linux kernel. A
remote attacker could exploit this flaw to cause a denial of service
(system crash) on
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2013-05-02·CVSS 1.9
CVE-2012-6548 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Mathias Krause discovered an information leak in the Linux kernel's UDF
file system implementation. A local user could exploit this flaw to examine
some of the kernel's heap memory. (CVE-2012-6548)
Mathias Krause discovered an information leak in the Linux kernel's ISO
9660 CDROM file system driver. A local user could exploit this flaw to
examine some of the kernel's heap memory. (CVE-2012-6549)
An integer overflow was discovered in the Direct Rendering Manager (DRM)
subsystem for the i915 video driver in the Linux kernel. A local user could
exploit this flaw to cause a denial of service (crash) or potentially
escalate privileges. (CVE-2013-0913)
Andrew Honig discovered a flaw in guest OS ti
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2013-05-02·CVSS 1.9
CVE-2012-6548 [LOW] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Mathias Krause discovered an information leak in the Linux kernel's UDF
file system implementation. A local user could exploit this flaw to examine
some of the kernel's heap memory. (CVE-2012-6548)
Mathias Krause discovered an information leak in the Linux kernel's ISO
9660 CDROM file system driver. A local user could exploit this flaw to
examine some of the kernel's heap memory. (CVE-2012-6549)
An integer overflow was discovered in the Direct Rendering Manager (DRM)
subsystem for the i915 video driver in the Linux kernel. A local user could
exploit this flaw to cause a denial of service (crash) or potentially
escalate privileges. (CVE-2013-0913)
A format-string bug was discovered in
Ubuntu
Linux kernel (Quantal HWE) vulnerabilities
vendor_ubuntu·2013-05-01·CVSS 1.9
CVE-2012-6548 [LOW] Linux kernel (Quantal HWE) vulnerabilities
Title: Linux kernel (Quantal HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Mathias Krause discovered an information leak in the Linux kernel's UDF
file system implementation. A local user could exploit this flaw to examine
some of the kernel's heap memory. (CVE-2012-6548)
Mathias Krause discovered an information leak in the Linux kernel's ISO
9660 CDROM file system driver. A local user could exploit this flaw to
examine some of the kernel's heap memory. (CVE-2012-6549)
An integer overflow was discovered in the Direct Rendering Manager (DRM)
subsystem for the i915 video driver in the Linux kernel. A local user could
exploit this flaw to cause a denial of service (crash) or potentially
escalate privileges. (CVE-2013-0913)
Andrew Honig discovered a flaw
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2013-05-01·CVSS 1.9
CVE-2012-6548 [LOW] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Mathias Krause discovered an information leak in the Linux kernel's UDF
file system implementation. A local user could exploit this flaw to examine
some of the kernel's heap memory. (CVE-2012-6548)
Mathias Krause discovered an information leak in the Linux kernel's ISO
9660 CDROM file system driver. A local user could exploit this flaw to
examine some of the kernel's heap memory. (CVE-2012-6549)
An integer overflow was discovered in the Direct Rendering Manager (DRM)
subsystem for the i915 video driver in the Linux kernel. A local user could
exploit this flaw to cause a denial of service (crash) or potentially
escalate privileges. (CVE-2013-0913)
Andrew Honig discovered a use after f
Red Hat
kernel: sctp: duplicate cookie handling NULL pointer dereference
vendor_redhat·2013-03-13·CVSS 5.4
CVE-2013-2206 [MEDIUM] CWE-476 kernel: sctp: duplicate cookie handling NULL pointer dereference
kernel: sctp: duplicate cookie handling NULL pointer dereference
The sctp_sf_do_5_2_4_dupcook function in net/sctp/sm_statefuns.c in the SCTP implementation in the Linux kernel before 3.8.5 does not properly handle associations during the processing of a duplicate COOKIE ECHO chunk, which allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via crafted SCTP traffic.
Statement: This issue does affect Linux kernel packages as shipped with Red Hat Enterprise Linux 5 and 6.
This issue does not affect Linux kernel packages as shipped with Red Hat Enterprise MRG 2 as they already contain the fix.
Package: realtime-kernel (Red Hat Enterprise MRG 2) - Not affected
Debian
CVE-2013-2206: linux - The sctp_sf_do_5_2_4_dupcook function in net/sctp/sm_statefuns.c in the SCTP imp...
vendor_debian·2013·CVSS 5.4
CVE-2013-2206 [MEDIUM] CVE-2013-2206: linux - The sctp_sf_do_5_2_4_dupcook function in net/sctp/sm_statefuns.c in the SCTP imp...
The sctp_sf_do_5_2_4_dupcook function in net/sctp/sm_statefuns.c in the SCTP implementation in the Linux kernel before 3.8.5 does not properly handle associations during the processing of a duplicate COOKIE ECHO chunk, which allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via crafted SCTP traffic.
Scope: local
bookworm: resolved (fixed in 3.9.4-1)
bullseye: resolved (fixed in 3.9.4-1)
forky: resolved (fixed in 3.9.4-1)
sid: resolved (fixed in 3.9.4-1)
trixie: resolved (fixed in 3.9.4-1)
GHSA
GHSA-xhcg-p7cj-pf6v: The sctp_sf_do_5_2_4_dupcook function in net/sctp/sm_statefuns
ghsa_unreviewed·2022-05-14
CVE-2013-2206 [MEDIUM] GHSA-xhcg-p7cj-pf6v: The sctp_sf_do_5_2_4_dupcook function in net/sctp/sm_statefuns
The sctp_sf_do_5_2_4_dupcook function in net/sctp/sm_statefuns.c in the SCTP implementation in the Linux kernel before 3.8.5 does not properly handle associations during the processing of a duplicate COOKIE ECHO chunk, which allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via crafted SCTP traffic.
OSV
CVE-2013-2206: The sctp_sf_do_5_2_4_dupcook function in net/sctp/sm_statefuns
osv·2013-07-04·CVSS 5.4
CVE-2013-2206 [MEDIUM] CVE-2013-2206: The sctp_sf_do_5_2_4_dupcook function in net/sctp/sm_statefuns
The sctp_sf_do_5_2_4_dupcook function in net/sctp/sm_statefuns.c in the SCTP implementation in the Linux kernel before 3.8.5 does not properly handle associations during the processing of a duplicate COOKIE ECHO chunk, which allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via crafted SCTP traffic.
No detection rules found.
No public exploits indexed.
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=f2815633504b442ca0b0605c16bf3d88a3a0fceahttp://lists.opensuse.org/opensuse-security-announce/2013-11/msg00020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-11/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-11/msg00023.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-11/msg00024.htmlhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00129.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1166.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1173.htmlhttp://www.debian.org/security/2013/dsa-2766http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.8.5http://www.openwall.com/lists/oss-security/2013/06/21/1http://www.ubuntu.com/usn/USN-1939-1https://bugzilla.redhat.com/show_bug.cgi?id=976562https://github.com/torvalds/linux/commit/f2815633504b442ca0b0605c16bf3d88a3a0fceahttp://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=f2815633504b442ca0b0605c16bf3d88a3a0fceahttp://lists.opensuse.org/opensuse-security-announce/2013-11/msg00020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-11/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-11/msg00023.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-11/msg00024.htmlhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00129.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1166.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1173.htmlhttp://www.debian.org/security/2013/dsa-2766http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.8.5http://www.openwall.com/lists/oss-security/2013/06/21/1http://www.ubuntu.com/usn/USN-1939-1https://bugzilla.redhat.com/show_bug.cgi?id=976562https://github.com/torvalds/linux/commit/f2815633504b442ca0b0605c16bf3d88a3a0fcea
2013-07-04
Published