PT-2021-7751 · Linux+9 · Linux+9

Published

2021-09-08

·

Updated

2023-08-14

·

CVE-2021-3772

CVSS v3.1

6.5

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions Linux (affected versions not specified)
Description A flaw was found in the Linux SCTP stack, allowing a blind attacker to kill an existing SCTP association through invalid chunks if the attacker knows the IP-addresses and port numbers being used and can send packets with spoofed IP addresses. The vulnerability is related to the lack of VTAG verification in received user blocks and the incorrect use of the ABORT flag in response to these blocks. This can be exploited by a remote attacker to cause a denial of service, closing the connection.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2022:1988
ALT-PU-2021-3330
ALT-PU-2021-3358
ALT-PU-2021-3563
ALT-PU-2021-3573
ALT-PU-2021-3660
ALT-PU-2022-1240
ALT-PU-2022-1419
ALT-PU-2022-1421
ALT-PU-2023-1814
ALT-PU-2023-4894
BDU:2023-02450
CESA-2022_1975
CESA-2022_1988
CVE-2021-3772
DLA-2941-1
DSA-5096-1
MGASA-2021-0507
MGASA-2021-0508
OESA-2021-1433
OPENSUSE-SU-2021:1477-1
OPENSUSE-SU-2021:3641-1
OPENSUSE-SU-2021:3675-1
OPENSUSE-SU-2021:3876-1
OPENSUSE-SU-2021_1460-1
OPENSUSE-SU-2021_1477-1
OPENSUSE-SU-2021_3641-1
OPENSUSE-SU-2021_3655-1
OPENSUSE-SU-2021_3675-1
OPENSUSE-SU-2021_3876-1
RHSA-2022:1975
RHSA-2022:1988
RHSA-2022_1975
RHSA-2022_1988
RLSA-2022:1975
RLSA-2022:1988
SUSE-SU-2021:14849-1
SUSE-SU-2021:3640-1
SUSE-SU-2021:3641-1
SUSE-SU-2021:3642-1
SUSE-SU-2021:3658-1
SUSE-SU-2021:3675-1
SUSE-SU-2021:3723-1
SUSE-SU-2021:3754-1
SUSE-SU-2021:3848-1
SUSE-SU-2021:3876-1
SUSE-SU-2021:3929-1
SUSE-SU-2021:3935-1
SUSE-SU-2021:3969-1
SUSE-SU-2021:3972-1
SUSE-SU-2021_14849-1
USN-5165-1
USN-5265-1
USN-5466-1
USN-5467-1
USN-6001-1
USN-6013-1
USN-6014-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linux
Linuxmint
Red Hat
Rocky Linux
Suse
Ubuntu