First published: Fri Jan 15 2010(Updated: )
Description of problem: Reported by our customer, via IT#371682. a flaw was found in the sctp_rcv_ootb() function in the Linux kernel Stream Control Transmission Protocol (SCTP) implementation. A remote attacker could send a specially-crafted SCTP packet to a target system, resulting in a denial of service. Acknowledgements: Red Hat would like to thank Telesys Software for responsibly reporting this issue.
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Linux |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-555658 is classified as high due to the potential for denial of service attacks.
To fix REDHAT-BUG-555658, you should update the Linux kernel to the latest version provided by Red Hat.
Users of the Red Hat Linux kernel that utilize SCTP may be affected by REDHAT-BUG-555658.
An attacker can exploit REDHAT-BUG-555658 by sending a specially-crafted SCTP packet to achieve a denial of service.
REDHAT-BUG-555658 was reported following customer feedback through an internal ticket.