Nixpkgs security tracker

Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Suggestion detail

Dismissed
(max. allowed matches exceeded)
created 3 weeks, 6 days ago Activity log
  • Created & dismissed (max. allowed matches exceeded) suggestion
sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid

In the Linux kernel, the following vulnerability has been resolved: sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid sctp_auth_ep_add_chunkid() uses SCTP_NUM_CHUNK_TYPES (20) as the capacity limit for ep->auth_chunk_list, allowing it to hold up to 20 chunk entries (param_hdr.length up to 24). However, the copy destination asoc->c.auth_chunks in struct sctp_cookie is only SCTP_AUTH_MAX_CHUNKS (16) entries (20 bytes). When more than 16 chunks are added, sctp_association_init() memcpy overflows the destination by up to 4 bytes. Fix by using SCTP_AUTH_MAX_CHUNKS as the capacity limit, matching the destination capacity.

Affected products

Linux
  • <ff04b26794a16a8a879eb4fd2c02c2d6b03850e9
  • <886e28e14ab655012779016d251fef53d103aa12
  • <b6ea3dda09eb4d5caf7bbc00f857688cf9e98255
  • =<6.6.*
  • =<*
  • <2.6.24
  • =<6.18.*
  • ==2.6.24
  • =<6.12.*
  • =<7.1.*
  • <5a365f1e423444c5da7eb689a8661633dad43e48
  • <11092d79eb2b7c0068382f72fc2416d1786bb2e0