CVE-2015-1421
published 2015-03-16CVE-2015-1421: Use-after-free vulnerability in the sctp_assoc_update function in net/sctp/associola.c in the Linux kernel before 3.18.8 allows remote attackers to cause a…
PriorityP344critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
9.83%
95.0th percentile
Use-after-free vulnerability in the sctp_assoc_update function in net/sctp/associola.c in the Linux kernel before 3.18.8 allows remote attackers to cause a denial of service (slab corruption and panic) or possibly have unspecified other impact by triggering an INIT collision that leads to improper handling of shared-key data.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | linux | < linux 3.16.7-ckt4-3 (bookworm) | linux 3.16.7-ckt4-3 (bookworm) |
| linux | linux_kernel | >= 0 < 3.16.7-ckt4-3 | 3.16.7-ckt4-3 |
| linux | linux_kernel | >= 0 < 3.16.7-ckt4-3 | 3.16.7-ckt4-3 |
| linux | linux_kernel | >= 0 < 3.16.7-ckt4-3 | 3.16.7-ckt4-3 |
| linux | linux_kernel | >= 0 < 3.16.7-ckt4-3 | 3.16.7-ckt4-3 |
| linux | linux_kernel | >= 0 < 3.13.0-49.81 | 3.13.0-49.81 |
| linux | linux_kernel | >= 2.6.24 < 3.2.67 | 3.2.67 |
| linux | linux_kernel | >= 3.11 < 3.12.38 | 3.12.38 |
| linux | linux_kernel | >= 3.13 < 3.14.34 | 3.14.34 |
| linux | linux_kernel | >= 3.15 < 3.16.35 | 3.16.35 |
| linux | linux_kernel | >= 3.17 < 3.18.8 | 3.18.8 |
| linux | linux_kernel | >= 3.3 < 3.4.107 | 3.4.107 |
| linux | linux_kernel | >= 3.5 < 3.10.70 | 3.10.70 |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_debian10.0CRITICAL
vendor_redhat10.0CRITICAL
vendor_ubuntu10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-76xf-x995-63r2: Use-after-free vulnerability in the sctp_assoc_update function in net/sctp/associola
ghsa_unreviewed·2022-05-14
CVE-2015-1421 [HIGH] GHSA-76xf-x995-63r2: Use-after-free vulnerability in the sctp_assoc_update function in net/sctp/associola
Use-after-free vulnerability in the sctp_assoc_update function in net/sctp/associola.c in the Linux kernel before 3.18.8 allows remote attackers to cause a denial of service (slab corruption and panic) or possibly have unspecified other impact by triggering an INIT collision that leads to improper handling of shared-key data.
OSV
linux vulnerabilities
osv·2015-04-08·CVSS 10.0
CVE-2015-1421 [CRITICAL] linux vulnerabilities
linux vulnerabilities
Sun Baoliang discovered a use after free flaw in the Linux kernel's SCTP
(Stream Control Transmission Protocol) subsystem during INIT collisions. A
remote attacker could exploit this flaw to cause a denial of service
(system crash) or potentially escalate their privileges on the system.
(CVE-2015-1421)
Marcelo Leitner discovered a flaw in the Linux kernel's routing of packets
to too many different dsts/too fast. A remote attacker on the same subnet can exploit this
flaw to cause a denial of service (system crash). (CVE-2015-1465)
An integer overflow was discovered in the stack randomization feature of
the Linux kernel on 64 bit platforms. A local attacker could exploit this
flaw to bypass the Address Space Layout Randomization (ASLR) protection
mechanism. (CVE-2015
OSV
linux-lts-utopic vulnerabilities
osv·2015-03-24·CVSS 2.1
CVE-2013-7421 [LOW] linux-lts-utopic vulnerabilities
linux-lts-utopic vulnerabilities
A flaw was discovered in the automatic loading of modules in the crypto
subsystem of the Linux kernel. A local user could exploit this flaw to load
installed kernel modules, increasing the attack surface and potentially
using this to gain administrative privileges. (CVE-2013-7421)
A flaw was discovered in the crypto subsystem when screening module names
for automatic module loading if the name contained a valid crypto module
name, eg. vfat(aes). A local user could exploit this flaw to load installed
kernel modules, increasing the attack surface and potentially using this to
gain administrative privileges. (CVE-2014-9644)
Sun Baoliang discovered a use after free flaw in the Linux kernel's SCTP
(Stream Control Transmission Protocol) subsystem during INIT c
OSV
CVE-2015-1421: Use-after-free vulnerability in the sctp_assoc_update function in net/sctp/associola
osv·2015-03-16·CVSS 10.0
CVE-2015-1421 [CRITICAL] CVE-2015-1421: Use-after-free vulnerability in the sctp_assoc_update function in net/sctp/associola
Use-after-free vulnerability in the sctp_assoc_update function in net/sctp/associola.c in the Linux kernel before 3.18.8 allows remote attackers to cause a denial of service (slab corruption and panic) or possibly have unspecified other impact by triggering an INIT collision that leads to improper handling of shared-key data.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2015-04-08·CVSS 10.0
CVE-2015-1421 [CRITICAL] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Sun Baoliang discovered a use after free flaw in the Linux kernel's SCTP
(Stream Control Transmission Protocol) subsystem during INIT collisions. A
remote attacker could exploit this flaw to cause a denial of service
(system crash) or potentially escalate their privileges on the system.
(CVE-2015-1421)
Marcelo Leitner discovered a flaw in the Linux kernel's routing of packets
to too many different dsts/too fast. A remote attacker on the same subnet can exploit this
flaw to cause a denial of service (system crash). (CVE-2015-1465)
An integer overflow was discovered in the stack randomization feature of
the Linux kernel on 64 bit platforms. A local attacker could exploit this
flaw to bypass the
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2015-04-08·CVSS 10.0
CVE-2015-1421 [CRITICAL] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Sun Baoliang discovered a use after free flaw in the Linux kernel's SCTP
(Stream Control Transmission Protocol) subsystem during INIT collisions. A
remote attacker could exploit this flaw to cause a denial of service
(system crash) or potentially escalate their privileges on the system.
(CVE-2015-1421)
Marcelo Leitner discovered a flaw in the Linux kernel's routing of packets
to too many different dsts/too fast. A remote attacker on the same subnet can exploit this
flaw to cause a denial of service (system crash). (CVE-2015-1465)
An integer overflow was discovered in the stack randomization feature of
the Linux kernel on 64 bit platforms. A local attacker could exploit this
flaw
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2015-03-24·CVSS 2.1
CVE-2013-7421 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
A flaw was discovered in the automatic loading of modules in the crypto
subsystem of the Linux kernel. A local user could exploit this flaw to load
installed kernel modules, increasing the attack surface and potentially
using this to gain administrative privileges. (CVE-2013-7421)
A flaw was discovered in the crypto subsystem when screening module names
for automatic module loading if the name contained a valid crypto module
name, eg. vfat(aes). A local user could exploit this flaw to load installed
kernel modules, increasing the attack surface and potentially using this to
gain administrative privileges. (CVE-2014-9644)
Sun Baoliang discovered a use after free flaw in the Linux kernel's SCTP
Ubuntu
Linux kernel (Utopic HWE) vulnerabilities
vendor_ubuntu·2015-03-24·CVSS 2.1
CVE-2013-7421 [LOW] Linux kernel (Utopic HWE) vulnerabilities
Title: Linux kernel (Utopic HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A flaw was discovered in the automatic loading of modules in the crypto
subsystem of the Linux kernel. A local user could exploit this flaw to load
installed kernel modules, increasing the attack surface and potentially
using this to gain administrative privileges. (CVE-2013-7421)
A flaw was discovered in the crypto subsystem when screening module names
for automatic module loading if the name contained a valid crypto module
name, eg. vfat(aes). A local user could exploit this flaw to load installed
kernel modules, increasing the attack surface and potentially using this to
gain administrative privileges. (CVE-2014-9644)
Sun Baoliang discovered a use after free flaw in the Linux
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2015-03-24·CVSS 7.2
CVE-2014-7822 [HIGH] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
The Linux kernel's splice system call did not correctly validate its
parameters. A local, unprivileged user could exploit this flaw to cause a
denial of service (system crash). (CVE-2014-7822)
A flaw was discovered in how Thread Local Storage (TLS) is handled by the
task switching function in the Linux kernel for x86_64 based machines. A
local user could exploit this flaw to bypass the Address Space Layout
Radomization (ASLR) protection mechanism. (CVE-2014-9419)
Dmitry Chernenkov discovered a buffer overflow in eCryptfs' encrypted file
name decoding. A local unprivileged user could exploit this flaw to cause a
denial of service (system crash) or potentially gain administrative
privil
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2015-03-24·CVSS 7.2
CVE-2014-7822 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
The Linux kernel's splice system call did not correctly validate its
parameters. A local, unprivileged user could exploit this flaw to cause a
denial of service (system crash). (CVE-2014-7822)
A flaw was discovered in how Thread Local Storage (TLS) is handled by the
task switching function in the Linux kernel for x86_64 based machines. A
local user could exploit this flaw to bypass the Address Space Layout
Radomization (ASLR) protection mechanism. (CVE-2014-9419)
Dmitry Chernenkov discovered a buffer overflow in eCryptfs' encrypted file
name decoding. A local unprivileged user could exploit this flaw to cause a
denial of service (system crash) or potentially gain administrative
privileges. (C
Red Hat
kernel: net: slab corruption from use after free on INIT collisions
vendor_redhat·2015-01-22·CVSS 10.0
CVE-2015-1421 [CRITICAL] CWE-416 kernel: net: slab corruption from use after free on INIT collisions
kernel: net: slab corruption from use after free on INIT collisions
Use-after-free vulnerability in the sctp_assoc_update function in net/sctp/associola.c in the Linux kernel before 3.18.8 allows remote attackers to cause a denial of service (slab corruption and panic) or possibly have unspecified other impact by triggering an INIT collision that leads to improper handling of shared-key data.
A use-after-free flaw was found in the way the Linux kernel's SCTP implementation handled authentication key reference counting during INIT collisions. A remote attacker could use this flaw to crash the system or, potentially, escalate their privileges on the system.
Statement: This issue did not affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 5.
This issue affects the Lin
Debian
CVE-2015-1421: linux - Use-after-free vulnerability in the sctp_assoc_update function in net/sctp/assoc...
vendor_debian·2015·CVSS 10.0
CVE-2015-1421 [CRITICAL] CVE-2015-1421: linux - Use-after-free vulnerability in the sctp_assoc_update function in net/sctp/assoc...
Use-after-free vulnerability in the sctp_assoc_update function in net/sctp/associola.c in the Linux kernel before 3.18.8 allows remote attackers to cause a denial of service (slab corruption and panic) or possibly have unspecified other impact by triggering an INIT collision that leads to improper handling of shared-key data.
Scope: local
bookworm: resolved (fixed in 3.16.7-ckt4-3)
bullseye: resolved (fixed in 3.16.7-ckt4-3)
forky: resolved (fixed in 3.16.7-ckt4-3)
sid: resolved (fixed in 3.16.7-ckt4-3)
trixie: resolved (fixed in 3.16.7-ckt4-3)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-1421 kernel: net: slab corruption from use after free on INIT collisions
bugzilla·2015-02-26·CVSS 10.0
CVE-2015-1421 [CRITICAL] CVE-2015-1421 kernel: net: slab corruption from use after free on INIT collisions
CVE-2015-1421 kernel: net: slab corruption from use after free on INIT collisions
An use after free flaw was found in the Linux kernel SCTP implementation
handled auth keys reference counting during INIT collisions.
A remote user could use this flaw to crash the system or, though unlikely,
escalate their privileges on the system.
Upstream patch:
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=600ddd6825543962fb807884169e57b580dba208
Acknowledgements:
This issue was discovered by Sun Baoliang of Red Hat.
Discussion:
Statement:
This issue did not affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 5.
This issue affects the Linux kernel packages as shipped with Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG 2. Future Linux kern
Bugzilla
CVE-2015-1421 kernel: net: slab corruption from use after free on INIT collisions [fedora-all]
bugzilla·2015-02-26·CVSS 10.0
CVE-2015-1421 [CRITICAL] CVE-2015-1421 kernel: net: slab corruption from use after free on INIT collisions [fedora-all]
CVE-2015-1421 kernel: net: slab corruption from use after free on INIT collisions [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple suppo
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=600ddd6825543962fb807884169e57b580dba208http://lists.opensuse.org/opensuse-security-announce/2015-05/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00004.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0726.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0751.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0782.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0864.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1082.htmlhttp://www.debian.org/security/2015/dsa-3170http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.18.8http://www.openwall.com/lists/oss-security/2015/01/29/15http://www.securityfocus.com/bid/72356http://www.securitytracker.com/id/1032172http://www.ubuntu.com/usn/USN-2541-1http://www.ubuntu.com/usn/USN-2542-1http://www.ubuntu.com/usn/USN-2545-1http://www.ubuntu.com/usn/USN-2546-1http://www.ubuntu.com/usn/USN-2562-1http://www.ubuntu.com/usn/USN-2563-1https://bugzilla.redhat.com/show_bug.cgi?id=1196581https://github.com/torvalds/linux/commit/600ddd6825543962fb807884169e57b580dba208http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=600ddd6825543962fb807884169e57b580dba208http://lists.opensuse.org/opensuse-security-announce/2015-05/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00004.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0726.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0751.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0782.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0864.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1082.htmlhttp://www.debian.org/security/2015/dsa-3170http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.18.8http://www.openwall.com/lists/oss-security/2015/01/29/15http://www.securityfocus.com/bid/72356http://www.securitytracker.com/id/1032172http://www.ubuntu.com/usn/USN-2541-1http://www.ubuntu.com/usn/USN-2542-1http://www.ubuntu.com/usn/USN-2545-1http://www.ubuntu.com/usn/USN-2546-1http://www.ubuntu.com/usn/USN-2562-1http://www.ubuntu.com/usn/USN-2563-1https://bugzilla.redhat.com/show_bug.cgi?id=1196581https://github.com/torvalds/linux/commit/600ddd6825543962fb807884169e57b580dba208
2015-03-16
Published