CVE-2011-4348

Race condition in the sctp_rcv function in net/sctp/input.c in the Linux kernel before 2.6.29 allows remote attackers to cause a denial of service (system hang) via SCTP packets.  NOTE: in some environments, this issue exists because of an incomplete fix for CVE-2011-2482.
Race Condition
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.1 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:C
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 64%
VendorProductVersion
linuxlinux_kernel
𝑥
≤ 2.6.28.10
linuxlinux_kernel
2.6.28
linuxlinux_kernel
2.6.28.1
linuxlinux_kernel
2.6.28.2
linuxlinux_kernel
2.6.28.3
linuxlinux_kernel
2.6.28.4
linuxlinux_kernel
2.6.28.5
linuxlinux_kernel
2.6.28.6
linuxlinux_kernel
2.6.28.7
linuxlinux_kernel
2.6.28.8
linuxlinux_kernel
2.6.28.9
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
linux
oneiric
not-affected
natty
not-affected
maverick
not-affected
lucid
not-affected
hardy
not-affected
linux-ec2
oneiric
dne
natty
dne
maverick
ignored
lucid
not-affected
hardy
dne
linux-fsl-imx51
oneiric
dne
natty
dne
maverick
dne
lucid
not-affected
hardy
dne
linux-lts-backport-maverick
oneiric
dne
natty
dne
maverick
dne
lucid
not-affected
hardy
dne
linux-lts-backport-natty
oneiric
dne
natty
dne
maverick
dne
lucid
not-affected
hardy
dne
linux-lts-backport-oneiric
oneiric
dne
natty
dne
maverick
dne
lucid
not-affected
hardy
dne
linux-mvl-dove
oneiric
dne
natty
dne
maverick
not-affected
lucid
not-affected
hardy
dne
linux-ti-omap4
oneiric
not-affected
natty
not-affected
maverick
not-affected
lucid
dne
hardy
dne