CVE-2014-0101 Details
Description
The sctp_sf_do_5_1D_ce function in net/sctp/sm_statefuns.c in the Linux kernel through 3.13.6 does not validate certain auth_enable and auth_capable fields before making an sctp_sf_authenticate call, which allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) via an SCTP handshake with a modified INIT chunk and a crafted AUTH chunk before a COOKIE_ECHO chunk.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-476 | NULL Pointer Dereference | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 2.6.24, < 3.2.56 >= 3.3, < 3.4.84 >= 3.5, < 3.10.34 >= 3.11, < 3.12.15 >= 3.13, < 3.13.7 |
CPE
Remediation
| |
| redhat enterprise linux desktop | 6.0 |
CPE
Remediation
| |
| redhat enterprise linux eus | 6.3 6.4 6.5 |
CPE
Remediation
| |
| redhat enterprise linux server | 6.0 |
CPE
Remediation
| |
| redhat enterprise linux server aus | 6.4 6.5 |
CPE
Remediation
| |
| redhat enterprise linux server tus | 6.5 |
CPE
Remediation
| |
| redhat enterprise linux workstation | 6.0 |
CPE
Remediation
| |
| canonical ubuntu linux | 10.04 |
CPE
Remediation
| |
| f5 big-ip access policy manager | >= 11.1.0, <= 11.5.3 |
CPE
Remediation
| |
| f5 big-ip advanced firewall manager | >= 11.3.0, <= 11.5.3 |
CPE
Remediation
| |
| f5 big-ip analytics | >= 11.1.0, <= 11.5.3 |
CPE
Remediation
| |
| f5 big-ip application acceleration manager | >= 11.4.0, <= 11.5.3 |
CPE
Remediation
| |
| f5 big-ip application security manager | >= 11.1.0, <= 11.5.3 |
CPE
Remediation
| |
| f5 big-ip edge gateway | >= 11.1.0, <= 11.3.0 |
CPE
Remediation
| |
| f5 big-ip enterprise manager | >= 2.1.0, <= 2.3.0 >= 3.0.0, <= 3.1.1 |
CPE
Remediation
| |
| f5 big-ip global traffic manager | >= 11.1.0, <= 11.5.3 |
CPE
Remediation
| |
| f5 big-ip link controller | >= 11.1.0, <= 11.5.3 |
CPE
Remediation
| |
| f5 big-ip local traffic manager | >= 11.1.0, <= 11.5.3 |
CPE
Remediation
| |
| f5 big-ip policy enforcement manager | >= 11.3.0, <= 11.5.3 |
CPE
Remediation
| |
| f5 big-ip protocol security module | >= 11.1.0, <= 11.4.1 |
CPE
Remediation
| |
| f5 big-ip wan optimization manager | >= 11.1.0, <= 11.3.0 |
CPE
Remediation
| |
| f5 big-ip webaccelerator | >= 11.1.0, <= 11.3.0 |
CPE
Remediation
| |
| f5 big-iq adc | 4.5.0 |
CPE
Remediation
| |
| f5 big-iq centralized management | 4.6.0 |
CPE
Remediation
| |
| f5 big-iq cloud | >= 4.0.0, <= 4.5.0 |
CPE
Remediation
| |
| f5 big-iq device | >= 4.2.0, <= 4.5.0 |
CPE
Remediation
| |
| f5 big-iq security | >= 4.0.0, <= 4.5.0 |
CPE
Remediation
| |
Change History
11 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| May 6, 2026 | Status Change | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Feb 13, 2023 | CVE Modified | [email protected] |
| Feb 2, 2023 | CVE Modified | [email protected] |
| Jan 17, 2023 | Reanalysis | [email protected] |
| Aug 25, 2020 | Modified Analysis | [email protected] |
| Dec 16, 2017 | CVE Modified | [email protected] |
| Jan 7, 2017 | CVE Modified | [email protected] |
| Mar 11, 2014 | Initial Analysis | [email protected] |