CVE-2021-3772: Medium severity Linux Linux kernel vulnerability
A flaw was found in the Linux SCTP stack. A blind attacker may be able to kill an existing SCTP association through invalid chunks if the attacker knows the IP-addresses and port numbers being used and the attacker can send packets with spoofed IP addresses.
Affected Software
Remediation
Information
Patch Available
Patch Available
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2021-3772?
CVE-2021-3772 is classified as a medium severity vulnerability due to its potential to disrupt existing SCTP associations.
How do I fix CVE-2021-3772?
To remediate CVE-2021-3772, upgrade to the recommended kernel versions provided by your Linux distribution vendor.
Who is affected by CVE-2021-3772?
CVE-2021-3772 affects various Linux kernel versions, specifically those prior to specified patched versions from Red Hat and Debian.
What type of attack does CVE-2021-3772 enable?
CVE-2021-3772 allows a blind attacker to potentially terminate existing SCTP associations through the use of malicious packets.
Which Linux distributions are impacted by CVE-2021-3772?
CVE-2021-3772 impacts Red Hat Enterprise Linux, Debian, and other distributions using vulnerable Linux kernel versions.