← العودة للجدول
CVE-2016-9555
CVE-2016-9555 — The sctp_sf_ootb function in net/sctp/sm_statefuns.c in the Linux kernel before
📅 2016-11-28
🔴 Critical 🔥 No NVD DDoS Linux CVSS 9.8 🎯 EPSS 26.94%

📋 الوصف الكامل

The sctp_sf_ootb function in net/sctp/sm_statefuns.c in the Linux kernel before 4.8.8 lacks chunk-length checking for the first chunk, which allows remote attackers to cause a denial of service (out-of-bounds slab access) or possibly have unspecified other impact via crafted SCTP data.

💻 الأنظمة المتأثرة

Linux Kernel 6.x/5.15 LTS

⚠️ نوع التهديد

DDoS

🔗 CVE ID

CVE-2016-9555

📡 المصدر

NVD

✅ الحلول والتخفيف

Refer to CVE-2016-9555 NVD advisory

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←