CVE-2015-1421
EPSS 9.8%
Description
Use-after-free vulnerability in the sctp_assoc_update function in net/sctp/associola.c in the Linux kernel before 3.18.8 allows remote attackers to cause a denial of service (slab corruption and panic) or possibly have unspecified other impact by triggering an INIT collision that leads to improper handling of shared-key data.
How to fix CVE-2015-1421
To remediate CVE-2015-1421, upgrade the affected package to a fixed version below.
- Debian/linux—upgrade to 3.16.7-ckt4-3 or later
Is CVE-2015-1421 being exploited?
Moderate — EPSS is 9.8%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 3.16.7-ckt4-3