CVE-2014-3687 PUBLISHED

The sctp_assoc_lookup_asconf_ack function in net/sctp/associola.c in the SCTP implementation in the Linux kernel through 3.17.2 allows remote attackers to cause a denial of service (panic) via duplicate ASCONF chunks that trigger an incorrect uncork within the side-effect interpreter.

EPSS 3.72% · 87.9th percentile

Risk Scores

EPSS Score
3.72%
87.9th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSlinux0, 3.11.0-12.19, 3.12.0-1.3
Ubuntu:14.04:LTSlinux-lts-utopic0, 3.16.0-25.33~14.04.2

Timeline

References

Open in Interactive Console →