The sctp_association_free function in net/sctp/associola.c in the Linux kernel before 3.15.2 does not properly manage a certain backlog value, which allows remote attackers to cause a denial of service (socket outage) via a crafted SCTP packet.
| Software | From | Fixed in |
|---|---|---|
| linux / linux_kernel | - | 3.15.2 |
| suse / linux_enterprise_desktop | 11-sp3 | 11-sp3.x |
| suse / linux_enterprise_server | 11-sp3 | 11-sp3.x |
| suse / linux_enterprise_real_time_extension | 11-sp3 | 11-sp3.x |
| suse / linux_enterprise_server | 10-sp4 | 10-sp4.x |
| canonical / ubuntu_linux | 12.04 | 12.04.x |
| debian / debian_linux | 7.0 | 7.0.x |