Linux Kernel SCTP INIT-ACK AUTH Extension Remote Denial of Service Vulnerability

The Linux kernel is prone to a remote denial-of-service vulnerability because it fails to handle mismatched SCTP AUTH extension settings between peers.

Attackers can exploit this issue to cause a kernel panic, denying service to legitimate users.

Versions prior to Linux kernel 2.6.27-rc6-git6 are vulnerable.


 

Privacy Statement
Copyright 2010, SecurityFocus