PT-2014-1824 · Linux+5 · Linux Kernel+5

Published

2014-11-10

·

Updated

2023-02-13

·

CVE-2014-3687

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Red Hat Enterprise Linux kernel-bootwrapper-2.6.32 versions 2.6.32 Red Hat Enterprise Linux kernel-kdump-2.6.32 versions 2.6.32 Red Hat Enterprise Linux kernel-kdump-devel-2.6.32 versions 2.6.32 Red Hat Enterprise Linux kernel-debuginfo-common-s390x-2.6.32 versions 2.6.32 Red Hat Enterprise Linux kernel-kdump-debuginfo-2.6.32 versions 2.6.32 Linux kernel versions prior to 3.17.2
Description The issue affects the Linux kernel and Red Hat Enterprise Linux, allowing remote attackers to cause a denial of service or disrupt the confidentiality, integrity, and availability of protected information. The sctp assoc lookup asconf ack function in net/sctp/associola.c is specifically vulnerable to duplicate ASCONF chunks that trigger an incorrect uncork within the side-effect interpreter, leading to a panic.
Recommendations For Red Hat Enterprise Linux kernel-bootwrapper-2.6.32 version 2.6.32, update to a newer version that contains a fix for this issue. For Red Hat Enterprise Linux kernel-kdump-2.6.32 version 2.6.32, update to a newer version that contains a fix for this issue. For Red Hat Enterprise Linux kernel-kdump-devel-2.6.32 version 2.6.32, update to a newer version that contains a fix for this issue. For Red Hat Enterprise Linux kernel-debuginfo-common-s390x-2.6.32 version 2.6.32, update to a newer version that contains a fix for this issue. For Red Hat Enterprise Linux kernel-kdump-debuginfo-2.6.32 version 2.6.32, update to a newer version that contains a fix for this issue. For Linux kernel versions prior to 3.17.2, update to version 3.17.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the sctp assoc lookup asconf ack function until a patch is available.

Exploit

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-2380
ALT-PU-2014-2381
BDU:2015-06243
BDU:2015-06250
BDU:2015-06263
BDU:2015-06264
BDU:2015-06265
CESA-2014_1971
CESA-2014_1997
CVE-2014-3687
DLA-118-1
DSA-3060-1
OPENSUSE-SU-2014_1677-1
OPENSUSE-SU-2014_1678-1
RHSA-2014:1971
RHSA-2014:1997
RHSA-2014_1971
RHSA-2014_1997
RHSA-2015:0043
RHSA-2015:0062
RHSA-2015:0115
SUSE-RU-2015:0621-1
SUSE-SU-2015:0481-1
SUSE-SU-2015:0529-1
SUSE-SU-2015:0581-1
SUSE-SU-2015:0652-1
SUSE-SU-2015:0736-1
SUSE-SU-2015:1174-1
SUSE-SU-2015:1376-1
SUSE-SU-2015:1489-1
SUSE-SU-2015_0178-1
USN-2417-1
USN-2418-1
USN-2441-1
USN-2442-1
USN-2445-1
USN-2446-1
USN-2447-1
USN-2447-2
USN-2448-1

Affected Products

Alt Linux
Centos
Linux Kernel
Red Hat
Suse
Ubuntu