The IPv6 SCTP implementation in net/sctp/ipv6.c in the Linux kernel through 3.11.1 uses data structures and function calls that do not trigger an intended configuration of IPsec encryption, which allows remote attackers to obtain sensitive information by sniffing the network.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade linux-grsec | Aug 30, 2017 | Sep 25, 2013 |
| Debian | — | Upgrade linux | Jul 30, 2024 | Sep 25, 2013 |
| Oracle_linux | — | Upgrade kernel-uek | Oct 16, 2024 | Sep 25, 2013 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Dec 6, 2010 |
| Ubuntu | — | Upgrade linux-image-3.2.0-57-virtualUpgrade linux-image-3.2.0-57-highbankUpgrade linux-image-3.2.0-57-genericUpgrade linux-image-3.5.0-43-genericUpgrade linux-image-3.5.0-236-omap4Upgrade linux-image-3.5.0-235-omap4Upgrade linux-image-3.8.0-34-genericUpgrade linux-image-3.5.0-43-highbankUpgrade linux-image-3.5.0-43-omapUpgrade linux-image-3.11.0-14-generic-lpaeUpgrade linux-image-3.2.0-57-omapUpgrade linux-image-3.5.0-43-powerpc64-smpUpgrade linux-image-3.2.0-57-powerpc64-smpUpgrade linux-image-3.2.0-1441-omap4Upgrade linux-image-3.2.0-57-generic-paeUpgrade linux-image-3.5.0-43-powerpc-smpUpgrade linux-image-3.2.0-57-powerpc-smpUpgrade linux-image-3.11.0-14-generic | Nov 8, 2024 | Sep 25, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub