Linux SCTP (lksctp) before 2.6.17 allows remote attackers to cause a denial of service (deadlock) via a large number of small messages to a receiver application that cannot process the messages quickly enough, which leads to "spillover of the receive buffer."
| Software | From | Fixed in |
|---|---|---|
| lksctp / stream_control_transmission_protocol | - | 2.6.17 |
| canonical / ubuntu_linux | 5.04 | 5.04.x |
| canonical / ubuntu_linux | 5.10 | 5.10.x |
| canonical / ubuntu_linux | 6.06 | 6.06.x |