PT-2015-1017 · Linux+5 · Linux Kernel+5

Sun Baoliang

·

Publicado

2015-02-17

·

Atualizado

2022-11-03

·

CVE-2015-1421

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Red Hat Enterprise Linux kernel versions prior to 3.18.8 Ubuntu linux-image-3.16.0 Ubuntu linux-image-3.2.0
Description The issue concerns multiple vulnerabilities in the Linux kernel, specifically affecting Red Hat Enterprise Linux and Ubuntu. These vulnerabilities can be exploited remotely, potentially leading to a disruption of confidentiality, integrity, and availability of protected information. The vulnerabilities can cause a denial of service, slab corruption, and panic, or possibly have unspecified other impacts. This is achieved by triggering an INIT collision that leads to improper handling of shared-key data in the sctp assoc update function in net/sctp/associola.c.
Recommendations For Red Hat Enterprise Linux kernel versions prior to 3.18.8: Update to a version 3.18.8 or later. For Ubuntu linux-image-3.16.0 and linux-image-3.2.0: Update to a newer version that includes the fix for this issue. As a temporary workaround, consider restricting access to the vulnerable sctp assoc update function until a patch is available.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2015-1186
ALT-PU-2015-1237
BDU:2015-09825
BDU:2015-09826
BDU:2015-09827
BDU:2015-09828
BDU:2015-09829
BDU:2015-09830
BDU:2015-09831
BDU:2015-09832
BDU:2015-09833
BDU:2015-09834
BDU:2015-09835
BDU:2015-09836
BDU:2015-09837
BDU:2015-09838
BDU:2015-09846
BDU:2015-09847
CESA-2015_0726
CESA-2015_0864
CVE-2015-1421
DLA-155-1
DSA-3170-1
MGASA-2015-0070
MGASA-2015-0076
MGASA-2015-0077
MGASA-2015-0078
OPENSUSE-SU-2015_0713-1
OPENSUSE-SU-2016_0301-1
RHSA-2015:0726
RHSA-2015:0727
RHSA-2015:0751
RHSA-2015:0782
RHSA-2015:0864
RHSA-2015:1030
RHSA-2015:1082
RHSA-2015_0726
RHSA-2015_0727
RHSA-2015_0864
SUSE-RU-2015:0621-1
SUSE-SU-2015:0581-1
SUSE-SU-2015:0736-1
SUSE-SU-2015:0832-1
SUSE-SU-2015:1174-1
SUSE-SU-2015:1376-1
SUSE-SU-2015:1478-1
USN-2541-1
USN-2542-1
USN-2545-1
USN-2546-1
USN-2562-1
USN-2563-1

Produtos afetados

Alt Linux
Centos
Linux Kernel
Red Hat
Suse
Ubuntu