CVE-2014-5077
EPSS 5.8%
Description
The sctp_assoc_update function in net/sctp/associola.c in the Linux kernel through 3.15.8, when SCTP authentication is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and OOPS) by starting to establish an association between two endpoints immediately after an exchange of INIT and INIT ACK chunks to establish an earlier association between these endpoints in the opposite direction.
How to fix CVE-2014-5077
To remediate CVE-2014-5077, upgrade the affected package to a fixed version below.
- Debian/linux—upgrade to 3.14.15-1 or later
Is CVE-2014-5077 being exploited?
Moderate — EPSS is 5.8%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 3.14.15-1