CVE-2006-2271: High severity lksctp lksctp vulnerability
Published May 9, 2006
·Updated
The ECNE chunk handling in Linux SCTP (lksctp) before 2.6.17 allows remote attackers to cause a denial of service (kernel panic) via an unexpected chunk when the session is in CLOSED state.
Affected Software
10 affected components
lksctp lksctp=2.6.0_test1_0.7.2
lksctp lksctp=2.6.0_test4_0.7.3
lksctp lksctp=2.6.2_0.9.0
lksctp lksctp=2.6.3_1.0.0
lksctp lksctp=2.6.6_1.0.1
lksctp lksctp=2.6.10_1.0.2
lksctp lksctp=2.6.13_1.0.3
lksctp lksctp=2.6.14_1.0.4
lksctp lksctp=2.6.15_1.0.5
lksctp lksctp=2.6.16_1.0.6
Remediation
Patch Available
Patch Available
Event History
May 9, 2006
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-2271?
CVE-2006-2271 has been classified as a denial of service vulnerability that can lead to a kernel panic.
2
How do I fix CVE-2006-2271?
To fix CVE-2006-2271, you should update Linux SCTP to version 2.6.17 or later.
3
What software is affected by CVE-2006-2271?
CVE-2006-2271 affects various versions of Linux SCTP, specifically versions before 2.6.17.
4
Can CVE-2006-2271 be exploited remotely?
Yes, CVE-2006-2271 can be exploited by remote attackers through unexpected ECNE chunks.
5
What impact does CVE-2006-2271 have on the system?
The impact of CVE-2006-2271 is a denial of service, resulting in the crashing of the system's kernel.