Secunia Logo  
 
Linux Kernel SCTP Denial of Service Vulnerabilities
Secunia Advisory: SA19990
Release Date: 2006-05-09
Last Update: 2006-05-10
Popularity: 10,589 views

Critical:
Moderately critical
Impact: DoS
Where: From remote
Solution Status: Vendor Patch

OS:Linux Kernel 2.6.x

Subscribe: Instant alerts on relevant vulnerabilities

CVE reference:CVE-2006-2271
CVE-2006-2272
CVE-2006-2274
CVE-2006-2275


Description:
Some vulnerabilities have been reported in the Linux Kernel, which can be exploited by malicious people to cause a DoS (Denial of Service).

1) An incorrect use of state table entries in the SCTP code when certain ECNE chunks are received in CLOSED state can be exploited to cause kernel panic via a specially crafted packet.

2) An error in the handling of incoming IP-fragmented SCTP control chunks can be exploited to cause kernel panic via fragmented COOKIE_ECHO and HEARTBEAT chunks.

3) An infinite recursion error in the "sctp_skb_pull()" function of lksctp can be exploited to crash the system during message reassembly via a specially crafted packet that contains two or more DATA fragments of a message.

4) An deadlock error within the handling of the receive buffer in SCTP can be exploited to cause a DoS via a large number of small messages sent to a receiver application that causes it to run of receive buffer space.

The vulnerabilities have been reported in version 2.6.16. Other versions may also be affected.

Solution:
Update to version 2.6.16.15.
http://kernel.org/

Provided and/or discovered by:
1-2) Mu Security research team
3-4) Reported by vendor.

Changelog:
2006-05-10: Added information of additional vulnerabilities. Updated "Description", "Solution", "Original Advisory" and credit sections.

Original Advisory:
http://labs.musecurity.com/advisories/MU-200605-01.txt

Kernel.org:
http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.15
http://www.kernel.org/git/?p=linux/ke...9baa0bb7a4064e6d0c99e8f479673120a9f28
http://www.kernel.org/git/?p=linux/ke...85c13b394cd1b74acc196f1d7990a3e0a484d
http://www.kernel.org/git/?p=linux/ke...58c671804a3829d822fc3ccc3eff534b1aaa0
http://www.kernel.org/git/?p=linux/ke...a2cd09dd7b3fbc99a1879a54090fd6db16f0c


Track this Secunia Advisory
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.

Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.

About this Secunia Advisory
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
  
Latest Advisories

Send Feedback to Secunia
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.

Most Popular - 3 Hours

1. Interstage HTTP Server mod_proxy_ftp Cross-Site Scripting // 33 views
2. XOOPS "mydirname" PHP Code Injection Vulnerability // 30 views
3. OpenBSD update for OpenSSL // 28 views
4. Sun Java JDK / JRE Multiple Vulnerabilities // 26 views
5. Adobe Flash Player Multiple Security Issues and Vulnerabilities // 25 views
6. Openfire Multiple Vulnerabilities // 25 views
7. Asterisk User Account Enumeration Weakness // 25 views
8. Serv-U Denial of Service Vulnerability // 24 views
9. Pizzis CMS "idvar" SQL Injection Vulnerability // 23 views
10. MODx "searchid" SQL Injection Vulnerability // 23 views