CVE-2014-3688 PUBLISHED

The SCTP implementation in the Linux kernel before 3.17.4 allows remote attackers to cause a denial of service (memory consumption) by triggering a large number of chunks in an association's output queue, as demonstrated by ASCONF probes, related to net/sctp/inqueue.c and net/sctp/sm_statefuns.c.

EPSS 2.62% · 85.5th percentile

Risk Scores

EPSS Score
2.62%
85.5th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSlinux-lts-utopic0, 3.16.0-25.33~14.04.2
Ubuntu:14.04:LTSlinux3.12.0-1.3, 3.12.0-2.5, 3.12.0-2.7

Timeline

References

Open in Interactive Console →