7.8
CVSSv2

CVE-2006-2271

Published: 09/05/2006 Updated: 07/11/2023
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 695
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

The ECNE chunk handling in Linux SCTP (lksctp) prior to 2.6.17 allows remote malicious users to cause a denial of service (kernel panic) via an unexpected chunk when the session is in CLOSED state.

Vulnerable Product Search on Vulmon Subscribe to Product

lksctp lksctp 2.6.0 test1 0.7.2

lksctp lksctp 2.6.2 0.9.0

lksctp lksctp 2.6.15 1.0.5

lksctp lksctp 2.6.0 test4 0.7.3

lksctp lksctp 2.6.13 1.0.3

lksctp lksctp 2.6.16 1.0.6

lksctp lksctp 2.6.10 1.0.2

lksctp lksctp 2.6.6 1.0.1

lksctp lksctp 2.6.14 1.0.4

lksctp lksctp 2.6.3 1.0.0

Vendor Advisories

An integer overflow was discovered in the do_replace() function A local user process with the CAP_NET_ADMIN capability could exploit this to execute arbitrary commands with full root privileges However, none of Ubuntu’s supported packages use this capability with any non-root user, so this only affects you if you use some third party software l ...
Several local and remote vulnerabilities have been discovered in the Linux kernel that may lead to a denial of service or the execution of arbitrary code The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2005-3359 Franz Filz discovered that some socket calls permit causing inconsistent reference count ...