Lucene search

K
f5F5F5:K17242
HistorySep 10, 2015 - 12:00 a.m.

K17242 : Linux kernel SCTP vulnerability CVE-2015-1421

2015-09-1000:00:00
my.f5.com
32

AI Score

6.2

Confidence

High

EPSS

0.058

Percentile

93.5%

Security Advisory Description

Use-after-free vulnerability in the sctp_assoc_update function in net/sctp/associola.c in the Linux kernel before 3.18.8 allows remote attackers to cause a denial of service (slab corruption and panic) or possibly have unspecified other impact by triggering an INIT collision that leads to improper handling of shared-key data. (CVE-2015-1421)

Impact

Remote attackers may be able to cause a denial-of-service (DoS) attack on an affected system by triggering an INIT collision in the Stream Control Transmission Protocol (SCTP). This vulnerability does not affect SCTP functionality on the data plane, but does affect the SCTP kernel module on the control plane for BIG-IP, BIG-IQ, and Enterprise Manager systems.