UBUNTU-CVE-2015-8767
Dashboard / Vulnerabilities / UBUNTU-CVE-2015-8767
UBUNTU-CVE-2015-8767
Summary:
Details: net/sctp/sm_sideeffect.c in the Linux kernel before 4.3 does not properly manage the relationship between a lock and a socket, which allows local users to cause a denial of service (deadlock) via a crafted sctp_accept call.
References: https://ubuntu.com/security/CVE-2015-8767, https://git.kernel.org/linus/635682a14427d241bab7bbdeebb48a7d7b91638e, http://www.openwall.com/lists/oss-security/2016/01/11/4, https://bugzilla.redhat.com/show_bug.cgi?id=1297389, https://ubuntu.com/security/notices/USN-2931-1, https://ubuntu.com/security/notices/USN-2932-1, https://ubuntu.com/security/notices/USN-2930-1, https://ubuntu.com/security/notices/USN-2930-2, https://ubuntu.com/security/notices/USN-2930-3, https://ubuntu.com/security/notices/USN-2967-2, https://ubuntu.com/security/notices/USN-2967-1, https://ubuntu.com/security/notices/USN-3083-2, https://ubuntu.com/security/notices/USN-3083-1, https://www.cve.org/CVERecord?id=CVE-2015-8767
Affected packages
Package
Name: linux
Purl: pkg:deb/ubuntu/linux?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
