CVE-2015-3212
published 2015-08-31CVE-2015-3212: Race condition in net/sctp/socket.c in the Linux kernel before 4.1.2 allows local users to cause a denial of service (list corruption and panic) via a rapid…
PriorityP415medium4.9CVSS 2.0
AVLACLAuNCNINAC
EPSS
0.34%
27.2th percentile
Race condition in net/sctp/socket.c in the Linux kernel before 4.1.2 allows local users to cause a denial of service (list corruption and panic) via a rapid series of system calls related to sockets, as demonstrated by setsockopt calls.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.0.8-1 (bookworm) | linux 4.0.8-1 (bookworm) |
| linux | linux_kernel | <= 4.1.1 | — |
| linux | linux_kernel | >= 0 < 4.0.8-1 | 4.0.8-1 |
| linux | linux_kernel | >= 0 < 4.0.8-1 | 4.0.8-1 |
| linux | linux_kernel | >= 0 < 4.0.8-1 | 4.0.8-1 |
| linux | linux_kernel | >= 0 < 4.0.8-1 | 4.0.8-1 |
CVSS provenance
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv4.9MEDIUM
vendor_debian4.9MEDIUM
vendor_redhat4.9MEDIUM
vendor_ubuntu4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5g2m-574j-wg7c: Race condition in net/sctp/socket
ghsa_unreviewed·2022-05-14
CVE-2015-3212 [MEDIUM] CWE-362 GHSA-5g2m-574j-wg7c: Race condition in net/sctp/socket
Race condition in net/sctp/socket.c in the Linux kernel before 4.1.2 allows local users to cause a denial of service (list corruption and panic) via a rapid series of system calls related to sockets, as demonstrated by setsockopt calls.
OSV
CVE-2015-3212: Race condition in net/sctp/socket
osv·2015-08-31·CVSS 4.9
CVE-2015-3212 [MEDIUM] CVE-2015-3212: Race condition in net/sctp/socket
Race condition in net/sctp/socket.c in the Linux kernel before 4.1.2 allows local users to cause a denial of service (list corruption and panic) via a rapid series of system calls related to sockets, as demonstrated by setsockopt calls.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2015-08-18·CVSS 4.9
CVE-2015-3212 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Marcelo Ricardo Leitner discovered a race condition in the Linux kernel's
SCTP address configuration lists when using Address Configuration Change
(ASCONF) options on a socket. An unprivileged local user could exploit this
flaw to cause a denial of service (system crash). (CVE-2015-3212)
A flaw was discovered in how the Linux kernel handles invalid UDP
checksums. A remote attacker could exploit this flaw to cause a denial of
service using a flood of UDP packets with invalid checksums.
(CVE-2015-5364)
A flaw was discovered in how the Linux kernel handles invalid UDP
checksums. A remote attacker can cause a denial of service against
applications that use epoll by injecting a single packet with
Ubuntu
Linux kernel vulnerability
vendor_ubuntu·2015-08-18
CVE-2015-3212 Linux kernel vulnerability
Title: Linux kernel vulnerability
Summary: The system could be made to crash under certain conditions.
Marcelo Ricardo Leitner discovered a race condition in the Linux kernel's
SCTP address configuration lists when using Address Configuration Change
(ASCONF) options on a socket. An unprivileged local user could exploit this
flaw to cause a denial of service (system crash).
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work
Ubuntu
Linux kernel (Trusty HWE) vulnerability
vendor_ubuntu·2015-08-18
CVE-2015-3212 Linux kernel (Trusty HWE) vulnerability
Title: Linux kernel (Trusty HWE) vulnerability
Summary: The system could be made to crash under certain conditions.
Marcelo Ricardo Leitner discovered a race condition in the Linux kernel's
SCTP address configuration lists when using Address Configuration Change
(ASCONF) options on a socket. An unprivileged local user could exploit this
flaw to cause a denial of service (system crash).
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get module
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2015-08-18·CVSS 4.9
CVE-2015-3212 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Marcelo Ricardo Leitner discovered a race condition in the Linux kernel's
SCTP address configuration lists when using Address Configuration Change
(ASCONF) options on a socket. An unprivileged local user could exploit this
flaw to cause a denial of service (system crash). (CVE-2015-3212)
A flaw was discovered in how the Linux kernel handles invalid UDP
checksums. A remote attacker could exploit this flaw to cause a denial of
service using a flood of UDP packets with invalid checksums.
(CVE-2015-5364)
A flaw was discovered in how the Linux kernel handles invalid UDP
checksums. A remote attacker can cause a denial of service against
applications that use epoll by injecting a single pack
Ubuntu
Linux kernel (Vivid HWE) vulnerability
vendor_ubuntu·2015-08-18
CVE-2015-3212 Linux kernel (Vivid HWE) vulnerability
Title: Linux kernel (Vivid HWE) vulnerability
Summary: The system could be made to crash under certain conditions.
Marcelo Ricardo Leitner discovered a race condition in the Linux kernel's
SCTP address configuration lists when using Address Configuration Change
(ASCONF) options on a socket. An unprivileged local user could exploit this
flaw to cause a denial of service (system crash).
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules
Ubuntu
Linux kernel (Utopic HWE) vulnerability
vendor_ubuntu·2015-08-18
CVE-2015-3212 Linux kernel (Utopic HWE) vulnerability
Title: Linux kernel (Utopic HWE) vulnerability
Summary: The system could be made to crash under certain conditions.
Marcelo Ricardo Leitner discovered a race condition in the Linux kernel's
SCTP address configuration lists when using Address Configuration Change
(ASCONF) options on a socket. An unprivileged local user could exploit this
flaw to cause a denial of service (system crash).
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get module
Red Hat
kernel: SCTP race condition allows list corruption and panic from userlevel
vendor_redhat·2015-06-30·CVSS 4.9
CVE-2015-3212 [MEDIUM] CWE-667 kernel: SCTP race condition allows list corruption and panic from userlevel
kernel: SCTP race condition allows list corruption and panic from userlevel
Race condition in net/sctp/socket.c in the Linux kernel before 4.1.2 allows local users to cause a denial of service (list corruption and panic) via a rapid series of system calls related to sockets, as demonstrated by setsockopt calls.
A race condition flaw was found in the way the Linux kernel's SCTP implementation handled Address Configuration lists when performing Address Configuration Change (ASCONF). A local attacker could use this flaw to crash the system via a race condition triggered by setting certain ASCONF options on a socket.
Statement: This issue does not affect the Linux kernels as shipped with Red Hat Enterprise Linux 5.
This issue affects the Linux kernels as shipped with Red Hat Enterprise Linu
Debian
CVE-2015-3212: linux - Race condition in net/sctp/socket.c in the Linux kernel before 4.1.2 allows loca...
vendor_debian·2015·CVSS 4.9
CVE-2015-3212 [MEDIUM] CVE-2015-3212: linux - Race condition in net/sctp/socket.c in the Linux kernel before 4.1.2 allows loca...
Race condition in net/sctp/socket.c in the Linux kernel before 4.1.2 allows local users to cause a denial of service (list corruption and panic) via a rapid series of system calls related to sockets, as demonstrated by setsockopt calls.
Scope: local
bookworm: resolved (fixed in 4.0.8-1)
bullseye: resolved (fixed in 4.0.8-1)
forky: resolved (fixed in 4.0.8-1)
sid: resolved (fixed in 4.0.8-1)
trixie: resolved (fixed in 4.0.8-1)
No detection rules found.
No public exploits indexed.
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=2d45a02d0166caf2627fe91897c6ffc3b19514c4http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00049.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-08/msg00011.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1778.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1787.htmlhttp://www.debian.org/security/2015/dsa-3329http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.1.2http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/76082http://www.securitytracker.com/id/1033169http://www.ubuntu.com/usn/USN-2713-1http://www.ubuntu.com/usn/USN-2714-1http://www.ubuntu.com/usn/USN-2715-1http://www.ubuntu.com/usn/USN-2716-1http://www.ubuntu.com/usn/USN-2717-1http://www.ubuntu.com/usn/USN-2718-1http://www.ubuntu.com/usn/USN-2719-1https://bugzilla.redhat.com/show_bug.cgi?id=1226442https://github.com/torvalds/linux/commit/2d45a02d0166caf2627fe91897c6ffc3b19514c4https://support.f5.com/csp/article/K05211147http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=2d45a02d0166caf2627fe91897c6ffc3b19514c4http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00049.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-08/msg00011.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1778.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1787.htmlhttp://www.debian.org/security/2015/dsa-3329http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.1.2http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/76082http://www.securitytracker.com/id/1033169http://www.ubuntu.com/usn/USN-2713-1http://www.ubuntu.com/usn/USN-2714-1http://www.ubuntu.com/usn/USN-2715-1http://www.ubuntu.com/usn/USN-2716-1http://www.ubuntu.com/usn/USN-2717-1http://www.ubuntu.com/usn/USN-2718-1http://www.ubuntu.com/usn/USN-2719-1https://bugzilla.redhat.com/show_bug.cgi?id=1226442https://github.com/torvalds/linux/commit/2d45a02d0166caf2627fe91897c6ffc3b19514c4https://support.f5.com/csp/article/K05211147
2015-08-31
Published