299,759
Total vulnerabilities in the database
The sctp_sf_ootb function in net/sctp/sm_statefuns.c in the Linux kernel before 4.8.8 lacks chunk-length checking for the first chunk, which allows remote attackers to cause a denial of service (out-of-bounds slab access) or possibly have unspecified other impact via crafted SCTP data.
| Software | From | Fixed in |
|---|---|---|
| linux / linux_kernel | 3.2 | 3.2.85 |
| linux / linux_kernel | 3.3 | 3.10.105 |
| linux / linux_kernel | 3.11 | 3.12.68 |
| linux / linux_kernel | 3.13 | 3.16.40 |
| linux / linux_kernel | 3.17 | 3.18.49 |
| linux / linux_kernel | 3.19 | 4.4.32 |
| linux / linux_kernel | 4.5.0 | 4.8.8 |