Thread-topic: [SA19926] Linux Kernel SCTP Netfilter Denial of Service Vulnerability
>
>
> TITLE:
> Linux Kernel SCTP Netfilter Denial of Service Vulnerability
>
> SECUNIA ADVISORY ID:
> SA19926
>
> VERIFY ADVISORY:
> http://secunia.com/advisories/19926/
>
> CRITICAL:
> Moderately critical
>
> IMPACT:
> DoS
>
> WHERE:
> From remote
>
> OPERATING SYSTEM:
> Linux Kernel 2.6.x
> http://secunia.com/product/2719/
>
> DESCRIPTION:
> A vulnerability has been reported in Linux Kernel, which can be
> exploited by malicious people to cause a DoS (Denial of Service).
>
> The vulnerability is caused due to missing checks on SCTP chunk sizes
> in the SCTP-netfilter code and may result in an infinite loop
> exhausting system resources.
>
> SOLUTION:
> Update to version 2.6.16.13 or later.
> http://kernel.org/
>
> PROVIDED AND/OR DISCOVERED BY:
> Reported by the vendor.
>
> ORIGINAL ADVISORY:
> http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.13
>
>