CVE-2008-3526: Integer Overflow
Integer overflow in the sctpsetsockoptauthkey function in net/sctp/socket.c in the Stream Control Transmission Protocol (sctp) implementation in the Linux kernel 2.6.24-rc1 through 2.6.26.3 allows remote attackers to cause a denial of service (panic) or possibly have unspecified other impact via a crafted scakeylength field associated with the SCTPAUTHKEY option.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-3526?
CVE-2008-3526 has been classified as a vulnerability that can lead to denial of service and potentially other unspecified impacts.
How do I fix CVE-2008-3526?
To fix CVE-2008-3526, update your Linux kernel to a version that is not affected by this vulnerability.
Which Linux kernel versions are affected by CVE-2008-3526?
CVE-2008-3526 affects multiple Linux kernel versions including 2.6.24-rc1 through 2.6.26.3.
Can CVE-2008-3526 be exploited remotely?
Yes, CVE-2008-3526 can be exploited by remote attackers to cause a denial of service.
What impact does CVE-2008-3526 have on system stability?
CVE-2008-3526 can cause the affected system to panic, resulting in loss of service and potential stability issues.