PT-2013-6319 · Linux+4 · Linux Kernel+5

Published

1970-01-01

·

Updated

2023-02-13

·

CVE-2014-0101

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SUSE Linux Enterprise kernel-pae-devel versions (affected versions not specified) SUSE Linux Enterprise kernel-xen-devel versions (affected versions not specified) SUSE Linux Enterprise gfs2-kmp-xen versions (affected versions not specified) SUSE Linux Enterprise kernel-ec2-devel versions (affected versions not specified) Linux kernel versions prior to 3.13.6
Description The issue concerns multiple vulnerabilities in various packages of the SUSE Linux Enterprise operating system, including kernel-pae-devel, kernel-xen-devel, gfs2-kmp-xen, and kernel-ec2-devel. These vulnerabilities can be exploited remotely, potentially leading to breaches of confidentiality, integrity, and availability of protected information. Specifically, the sctp sf do 5 1D ce function in net/sctp/sm statefuns.c of the Linux kernel does not properly validate auth enable and auth capable fields before making an sctp sf authenticate call. This allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) via an SCTP handshake with a modified INIT chunk and a crafted AUTH chunk before a COOKIE ECHO chunk. Remote users can also cause a denial of service (NULL pointer dereference) when using the SCTP network protocol.
Recommendations For SUSE Linux Enterprise kernel-pae-devel, consider disabling the vulnerable components until a patch is available. For SUSE Linux Enterprise kernel-xen-devel, restrict access to the vulnerable modules to minimize the risk of exploitation. For SUSE Linux Enterprise gfs2-kmp-xen, avoid using the affected package until the issue is resolved. For SUSE Linux Enterprise kernel-ec2-devel, consider applying configuration changes to mitigate the risk of remote exploitation. For Linux kernel versions prior to 3.13.6, update to a version 3.13.6 or later to resolve the issue. At the moment, there is no information about additional mitigation measures for these vulnerabilities.

Exploit

Fix

DoS

NULL Pointer Dereference

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-1355
ALT-PU-2014-1362
ALT-PU-2014-1375
ALT-PU-2014-1547
ALT-PU-2014-1606
BDU:2014-00102
BDU:2015-04307
BDU:2015-04308
BDU:2015-04309
BDU:2015-04310
CESA-2014_0328
CVE-2014-0101
DSA-2906-1
OPENSUSE-SU-2014_0677-1
OPENSUSE-SU-2014_0678-1
RHSA-2014:0328
RHSA-2014:0419
RHSA-2014:0432
RHSA-2014:0520
RHSA-2014_0328
SUSE-RU-2015:0621-1
SUSE-SU-2015:0481-1
SUSE-SU-2015:0581-1
SUSE-SU-2015:0652-1
SUSE-SU-2015:0736-1
SUSE-SU-2015:1174-1
SUSE-SU-2015:1376-1
USN-2173-1
USN-2174-1
USN-2221-1
USN-2223-1
USN-2224-1
USN-2225-1
USN-2227-1
USN-2228-1

Affected Products

Alt Linux
Centos
Linux Kernel
Red Hat
Suse Linux Enterprise
Suse