CVE-2014-4667
published 2014-07-03CVE-2014-4667: The sctp_association_free function in net/sctp/associola.c in the Linux kernel before 3.15.2 does not properly manage a certain backlog value, which allows…
PriorityP429medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
5.93%
92.5th percentile
The sctp_association_free function in net/sctp/associola.c in the Linux kernel before 3.15.2 does not properly manage a certain backlog value, which allows remote attackers to cause a denial of service (socket outage) via a crafted SCTP packet.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | linux | < linux 3.14.9-1 (bookworm) | linux 3.14.9-1 (bookworm) |
| linux | linux_kernel | < 3.15.2 | 3.15.2 |
| linux | linux_kernel | >= 0 < 3.14.9-1 | 3.14.9-1 |
| linux | linux_kernel | >= 0 < 3.14.9-1 | 3.14.9-1 |
| linux | linux_kernel | >= 0 < 3.14.9-1 | 3.14.9-1 |
| linux | linux_kernel | >= 0 < 3.14.9-1 | 3.14.9-1 |
| linux | linux_kernel | >= 0 < 3.13.0-35.62 | 3.13.0-35.62 |
| suse | linux_enterprise_desktop | — | — |
| suse | linux_enterprise_real_time_extension | — | — |
| suse | linux_enterprise_server | — | — |
| suse | linux_enterprise_server | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_ubuntu5.5MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2014-09-02·CVSS 3.3
CVE-2014-3917 [LOW] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
An flaw was discovered in the Linux kernel's audit subsystem when auditing
certain syscalls. A local attacker could exploit this flaw to obtain
potentially sensitive single-bit values from kernel memory or cause a
denial of service (OOPS). (CVE-2014-3917)
An information leak was discovered in the rd_mcp backend of the iSCSI
target subsystem in the Linux kernel. A local user could exploit this flaw
to obtain sensitive information from ramdisk_mcp memory by leveraging
access to a SCSI initiator. (CVE-2014-4027)
Sasha Levin reported an issue with the Linux kernel's shared memory
subsystem when used with range notifications and hole punching. A local
user could exploit this flaw to cause
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-09-02·CVSS 3.3
CVE-2014-3917 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
An flaw was discovered in the Linux kernel's audit subsystem when auditing
certain syscalls. A local attacker could exploit this flaw to obtain
potentially sensitive single-bit values from kernel memory or cause a
denial of service (OOPS). (CVE-2014-3917)
An information leak was discovered in the rd_mcp backend of the iSCSI
target subsystem in the Linux kernel. A local user could exploit this flaw
to obtain sensitive information from ramdisk_mcp memory by leveraging
access to a SCSI initiator. (CVE-2014-4027)
Sasha Levin reported an issue with the Linux kernel's shared memory
subsystem when used with range notifications and hole punching. A local
user could exploit this flaw to cause a denial
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2014-09-02·CVSS 5.5
CVE-2014-0155 [MEDIUM] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A flaw was discovered in the Linux kernel virtual machine's (kvm)
validation of interrupt requests (irq). A guest OS user could exploit this
flaw to cause a denial of service (host OS crash). (CVE-2014-0155)
Andy Lutomirski discovered a flaw in the authorization of netlink socket
operations when a socket is passed to a process of more privilege. A local
user could exploit this flaw to bypass access restrictions by having a
privileged executable do something it was not intended to do.
(CVE-2014-0181)
An information leak was discovered in the Linux kernels
aio_read_events_ring function. A local user could exploit this flaw to
obtain potentially sensitive information from kernel mem
Ubuntu
Linux kernel (EC2) vulnerabilities
vendor_ubuntu·2014-09-02·CVSS 5.5
CVE-2014-0203 [MEDIUM] Linux kernel (EC2) vulnerabilities
Title: Linux kernel (EC2) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A bug was discovered in the handling of pathname components when used with
an autofs direct mount. A local user could exploit this flaw to cause a
denial of service (system crash) via an open system call. (CVE-2014-0203)
Toralf Förster reported an error in the Linux kernels syscall auditing on
32 bit x86 platforms. A local user could exploit this flaw to cause a
denial of service (OOPS and system crash). (CVE-2014-4508)
An information leak was discovered in the control implemenation of the
Advanced Linux Sound Architecture (ALSA) subsystem in the Linux kernel. A
local user could exploit this flaw to obtain sensitive information from
kernel memory. (CVE-2014-4652)
A use-after-free flaw
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-09-02·CVSS 5.5
CVE-2014-0155 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
A flaw was discovered in the Linux kernel virtual machine's (kvm)
validation of interrupt requests (irq). A guest OS user could exploit this
flaw to cause a denial of service (host OS crash). (CVE-2014-0155)
Andy Lutomirski discovered a flaw in the authorization of netlink socket
operations when a socket is passed to a process of more privilege. A local
user could exploit this flaw to bypass access restrictions by having a
privileged executable do something it was not intended to do.
(CVE-2014-0181)
An information leak was discovered in the Linux kernels
aio_read_events_ring function. A local user could exploit this flaw to
obtain potentially sensitive information from kernel memory.
(CVE-201
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-09-02·CVSS 5.5
CVE-2014-0203 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
A bug was discovered in the handling of pathname components when used with
an autofs direct mount. A local user could exploit this flaw to cause a
denial of service (system crash) via an open system call. (CVE-2014-0203)
Toralf Förster reported an error in the Linux kernels syscall auditing on
32 bit x86 platforms. A local user could exploit this flaw to cause a
denial of service (OOPS and system crash). (CVE-2014-4508)
An information leak was discovered in the control implemenation of the
Advanced Linux Sound Architecture (ALSA) subsystem in the Linux kernel. A
local user could exploit this flaw to obtain sensitive information from
kernel memory. (CVE-2014-4652)
A use-after-free flaw was di
Red Hat
kernel: sctp: sk_ack_backlog wrap-around problem
vendor_redhat·2014-06-12·CVSS 5.0
CVE-2014-4667 [MEDIUM] CWE-190 kernel: sctp: sk_ack_backlog wrap-around problem
kernel: sctp: sk_ack_backlog wrap-around problem
The sctp_association_free function in net/sctp/associola.c in the Linux kernel before 3.15.2 does not properly manage a certain backlog value, which allows remote attackers to cause a denial of service (socket outage) via a crafted SCTP packet.
An integer underflow flaw was found in the way the Linux kernel's Stream Control Transmission Protocol (SCTP) implementation processed certain COOKIE_ECHO packets. By sending a specially crafted SCTP packet, a remote attacker could use this flaw to prevent legitimate connections to a particular SCTP server socket to be made.
Statement: This issue does not affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 5.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2014-4667: linux - The sctp_association_free function in net/sctp/associola.c in the Linux kernel b...
vendor_debian·2014·CVSS 5.0
CVE-2014-4667 [MEDIUM] CVE-2014-4667: linux - The sctp_association_free function in net/sctp/associola.c in the Linux kernel b...
The sctp_association_free function in net/sctp/associola.c in the Linux kernel before 3.15.2 does not properly manage a certain backlog value, which allows remote attackers to cause a denial of service (socket outage) via a crafted SCTP packet.
Scope: local
bookworm: resolved (fixed in 3.14.9-1)
bullseye: resolved (fixed in 3.14.9-1)
forky: resolved (fixed in 3.14.9-1)
sid: resolved (fixed in 3.14.9-1)
trixie: resolved (fixed in 3.14.9-1)
GHSA
GHSA-6f8q-p6j4-j3h5: The sctp_association_free function in net/sctp/associola
ghsa_unreviewed·2022-05-13
CVE-2014-4667 [MEDIUM] GHSA-6f8q-p6j4-j3h5: The sctp_association_free function in net/sctp/associola
The sctp_association_free function in net/sctp/associola.c in the Linux kernel before 3.15.2 does not properly manage a certain backlog value, which allows remote attackers to cause a denial of service (socket outage) via a crafted SCTP packet.
OSV
linux vulnerabilities
osv·2014-09-02·CVSS 5.5
CVE-2014-0155 [MEDIUM] linux vulnerabilities
linux vulnerabilities
A flaw was discovered in the Linux kernel virtual machine's (kvm)
validation of interrupt requests (irq). A guest OS user could exploit this
flaw to cause a denial of service (host OS crash). (CVE-2014-0155)
Andy Lutomirski discovered a flaw in the authorization of netlink socket
operations when a socket is passed to a process of more privilege. A local
user could exploit this flaw to bypass access restrictions by having a
privileged executable do something it was not intended to do.
(CVE-2014-0181)
An information leak was discovered in the Linux kernels
aio_read_events_ring function. A local user could exploit this flaw to
obtain potentially sensitive information from kernel memory.
(CVE-2014-0206)
A flaw was discovered in the Linux kernel's implementation of use
OSV
CVE-2014-4667: The sctp_association_free function in net/sctp/associola
osv·2014-07-03·CVSS 5.0
CVE-2014-4667 [MEDIUM] CVE-2014-4667: The sctp_association_free function in net/sctp/associola
The sctp_association_free function in net/sctp/associola.c in the Linux kernel before 3.15.2 does not properly manage a certain backlog value, which allows remote attackers to cause a denial of service (socket outage) via a crafted SCTP packet.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-4667 kernel: sctp: sk_ack_backlog wrap-around problem [fedora-all]
bugzilla·2014-06-27·CVSS 5.0
CVE-2014-4667 [MEDIUM] CVE-2014-4667 kernel: sctp: sk_ack_backlog wrap-around problem [fedora-all]
CVE-2014-4667 kernel: sctp: sk_ack_backlog wrap-around problem [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
NOTE: this issue affects multiple su
Bugzilla
CVE-2014-4667 kernel: sctp: sk_ack_backlog wrap-around problem
bugzilla·2014-06-27·CVSS 5.0
CVE-2014-4667 [MEDIUM] CVE-2014-4667 kernel: sctp: sk_ack_backlog wrap-around problem
CVE-2014-4667 kernel: sctp: sk_ack_backlog wrap-around problem
Description of the problem:
For a TCP-style socket, while processing the COOKIE_ECHO chunk in
sctp_sf_do_5_1D_ce(), after it has passed a series of sanity check, a
new association would be created in sctp_unpack_cookie(), but afterwards,
some processing maybe failed, and sctp_association_free() will be called
to free the previously allocated association, in sctp_association_free(),
sk_ack_backlog value is decremented for this socket, since the initial
value for sk_ack_backlog is 0, after the decrement, it will be 65535, a
wrap-around problem happens, and if we want to establish new associations
afterward in the same socket, ABORT would be triggered since sctp deem the
accept queue as full.
A remote attacker can block further
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=d3217b15a19a4779c39b212358a5c71d725822eehttp://linux.oracle.com/errata/ELSA-2014-3068.htmlhttp://linux.oracle.com/errata/ELSA-2014-3069.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-10/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-10/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00020.htmlhttp://secunia.com/advisories/59777http://secunia.com/advisories/59790http://secunia.com/advisories/60564http://secunia.com/advisories/60596http://www.debian.org/security/2014/dsa-2992http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.15.2http://www.openwall.com/lists/oss-security/2014/06/27/11http://www.securityfocus.com/bid/68224http://www.ubuntu.com/usn/USN-2334-1http://www.ubuntu.com/usn/USN-2335-1https://bugzilla.redhat.com/show_bug.cgi?id=1113967https://github.com/torvalds/linux/commit/d3217b15a19a4779c39b212358a5c71d725822eehttp://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=d3217b15a19a4779c39b212358a5c71d725822eehttp://linux.oracle.com/errata/ELSA-2014-3068.htmlhttp://linux.oracle.com/errata/ELSA-2014-3069.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-10/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-10/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00020.htmlhttp://secunia.com/advisories/59777http://secunia.com/advisories/59790http://secunia.com/advisories/60564http://secunia.com/advisories/60596http://www.debian.org/security/2014/dsa-2992http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.15.2http://www.openwall.com/lists/oss-security/2014/06/27/11http://www.securityfocus.com/bid/68224http://www.ubuntu.com/usn/USN-2334-1http://www.ubuntu.com/usn/USN-2335-1https://bugzilla.redhat.com/show_bug.cgi?id=1113967https://github.com/torvalds/linux/commit/d3217b15a19a4779c39b212358a5c71d725822ee
2014-07-03
Published