CVE-2008-2826
02.07.2008, 16:41
Integer overflow in the sctp_getsockopt_local_addrs_old function in net/sctp/socket.c in the Stream Control Transmission Protocol (sctp) functionality in the Linux kernel before 2.6.25.9 allows local users to cause a denial of service (resource consumption and system outage) via vectors involving a large addr_num field in an sctp_getaddrs_old data structure.Enginsight
| Vendor | Product | Version |
|---|---|---|
| linux | linux_kernel | 𝑥 < 2.6.25.9 |
| opensuse | opensuse | 10.3 |
| opensuse | opensuse | 11.0 |
| debian | debian_linux | 4.0 |
| canonical | ubuntu_linux | 6.06 |
| canonical | ubuntu_linux | 7.04 |
| canonical | ubuntu_linux | 7.10 |
| canonical | ubuntu_linux | 8.04 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Ubuntu Product | |||||||||
|---|---|---|---|---|---|---|---|---|---|
| linux |
| ||||||||
| linux-source-2.6.15 |
| ||||||||
| linux-source-2.6.20 |
| ||||||||
| linux-source-2.6.22 |
|
References