imPC@ndo IT

Tracker / CVE-2021-3772

CVE-2021-3772

Medium 6.5

A flaw was found in the Linux SCTP stack. A blind attacker may be able to kill an existing SCTP association through invalid chunks if the attacker knows the IP-addresses and port numbers being used and the attacker can send packets with spoofed IP addresses.

Affected products and versions

debian debian_linux
linux linux_kernel · … → 5.15.0
netapp e-series_santricity_os_controller
netapp h300s_firmware
netapp h410c_firmware
netapp h410s_firmware
netapp h500s_firmware
netapp h610c_firmware
netapp h610s_firmware
netapp h615c_firmware
netapp h700s_firmware
netapp hci_compute_node
netapp solidfire_\&_hci_management_node
netapp solidfire_\&_hci_storage_node
oracle communications_cloud_native_core_binding_support_function
oracle communications_cloud_native_core_network_exposure_function
oracle communications_cloud_native_core_policy
redhat enterprise_linux

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References