ubuntu · CVE-2014-3687

Quick triage

Priority: medium Published: 2014-11-10 00:00:00 UTC Updated: 2025-08-25 21:19:13 UTC

View at Official ubuntu advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2014-3687 medium priority: Ubuntu including 31 source packages (linux, linux-2.6, …), 285 status rows across 10 suites (lucid, precise, trusty, upstream, utopic, vivid, wily, xenial, yakkety, zesty): DNE 200, released 40, ignored 27, not-affected 18.

Description:

The sctp_assoc_lookup_asconf_ack function in net/sctp/associola.c in the SCTP implementation in the Linux kernel through 3.17.2 allows remote attackers to cause a denial of service (panic) via duplicate ASCONF chunks that trigger an incorrect uncork within the side-effect interpreter.

cvelogic Threat Intelligence