CVE-2008-2826 PUBLISHED CVSS 4.900000095367432 MEDIUM

Integer overflow in the sctp_getsockopt_local_addrs_old function in net/sctp/socket.c in the Stream Control Transmission Protocol (sctp) functionality in the Linux kernel before 2.6.25.9 allows local users to cause a denial of service (resource consumption and system outage) via vectors involving a large addr_num field in an sctp_getaddrs_old data structure.

EPSS 0.15% · 35.7th percentile

Risk Scores

CVSS v2.0
4.900000095367432
EPSS Score
0.15%
35.7th percentile

Affected Products

VendorProductVersions
opensuseopensuse10.3, 11.0
canonicalubuntu_linux7.04, 8.04, 7.10
n/an/an/a
debiandebian_linux4.0
linuxlinux_kernel0

Timeline

References

…and 6 more

Open in Interactive Console →