CVE-2008-3526
Summary
| CVE | CVE-2008-3526 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-08-27 20:41:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Integer overflow in the sctp_setsockopt_auth_key function in net/sctp/socket.c in the Stream Control Transmission Protocol (sctp) implementation in the Linux kernel 2.6.24-rc1 through 2.6.26.3 allows remote attackers to cause a denial of service (panic) or possibly have unspecified other impact via a crafted sca_keylength field associated with the SCTP_AUTH_KEY option. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
CompleteAV:N/AC:L/Au:N/C:N/I:N/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Linux | Linux Kernel | 2.6.24 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.24 | rc2 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.24 | rc3 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.24.1 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.24.2 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.24.3 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.24.4 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.24.5 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.24.6 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.24.7 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.24_rc1 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.24_rc4 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.24_rc5 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.25 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.25.1 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.25.10 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.25.11 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.25.12 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.25.13 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.25.14 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.25.15 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.25.2 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.25.3 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.25.4 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.25.5 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.25.6 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.25.7 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.25.8 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.25.9 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.26 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.26.1 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.26.2 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.26.3 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Support / Security / Advisories / / MDVSA-2008:223 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| Red Hat update for kernel - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Debian -- Security Information -- DSA-1636-1 linux-2.6.24 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| [security-announce] SUSE Security Announcement: Linux kernel (SUSE-SA:20 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Linux Kernel 'sctp_setsockopt_auth_key()' Remote Denial of Service Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| git.kernel.org | af854a3a-2127-422b-91ae-364da2661108 | git.kernel.org | |
| oss-security - CVE-2008-3526 Linux kernel sctp_setsockopt_auth_key() integer overflow | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| Ubuntu update for linux - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Debian update for linux-2.6.24 - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| USN-659-1: Linux kernel vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| CONFIRM:http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.26.y.git;a=commit;h=30c2235cbc477d4629983d440cdc4f496fec9246 | MITRE | git.kernel.org | |
| Red Hat Customer Portal | MITRE | access.redhat.com | |
| CVE-2008-3526 - Red Hat Customer Portal | MITRE | access.redhat.com | |
| 460093 – (CVE-2008-3526) CVE-2008-3526 Linux kernel sctp_setsockopt_auth_key() integer overflow | MITRE | bugzilla.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2009-01-15 | Tomas Hoger | This issue did not affect the versions of Linux kernel as shipped with Red Hat Enterprise Linux 2.1, 3, 4, and 5. It was addressed in Red Hat Enterprise MRG for RHEL-5 via: https://rhn.redhat.com/errata/RHSA-2008-0857.html |
There are currently no legacy QID mappings associated with this CVE.