Vulnerability Description
A flaw was found in the Linux SCTP stack. A blind attacker may be able to kill an existing SCTP association through invalid chunks if the attacker knows the IP-addresses and port numbers being used and the attacker can send packets with spoofed IP addresses.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | < 5.15.0 |
| Redhat | Enterprise Linux | 8.0 |
| Debian | Debian Linux | 9.0 |
| Oracle | Communications Cloud Native Core Binding Support Function | 22.1.3 |
| Oracle | Communications Cloud Native Core Network Exposure Function | 22.1.1 |
| Oracle | Communications Cloud Native Core Policy | 22.2.0 |
| Netapp | E-Series Santricity Os Controller | 11.0 |
| Netapp | Solidfire \& Hci Management Node | - |
| Netapp | Solidfire \& Hci Storage Node | - |
| Netapp | Hci Compute Node | - |
| Netapp | H300S Firmware | - |
| Netapp | H300S | - |
| Netapp | H500S Firmware | - |
| Netapp | H500S | - |
| Netapp | H700S Firmware | - |
| Netapp | H700S | - |
| Netapp | H410S Firmware | - |
| Netapp | H410S | - |
| Netapp | H410C Firmware | - |
| Netapp | H410C | - |
Related Weaknesses (CWE)
References
- https://bugzilla.redhat.com/show_bug.cgi?id=2000694Issue TrackingPatchThird Party Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=32Mailing ListPatchVendor Advisory
- https://github.com/torvalds/linux/commit/32f8807a48ae55be0e76880cfe8607a18b5bb0dPatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/03/msg00012.htmlMailing ListThird Party Advisory
- https://security.netapp.com/advisory/ntap-20221007-0001/Third Party Advisory
- https://ubuntu.com/security/CVE-2021-3772PatchThird Party Advisory
- https://www.debian.org/security/2022/dsa-5096Third Party Advisory
- https://www.oracle.com/security-alerts/cpujul2022.htmlPatchThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2000694Issue TrackingPatchThird Party Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=32Mailing ListPatchVendor Advisory
- https://github.com/torvalds/linux/commit/32f8807a48ae55be0e76880cfe8607a18b5bb0dPatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/03/msg00012.htmlMailing ListThird Party Advisory
- https://security.netapp.com/advisory/ntap-20221007-0001/Third Party Advisory
- https://ubuntu.com/security/CVE-2021-3772PatchThird Party Advisory
- https://www.debian.org/security/2022/dsa-5096Third Party Advisory
FAQ
What is CVE-2021-3772?
CVE-2021-3772 is a vulnerability with a CVSS score of 6.5 (MEDIUM). A flaw was found in the Linux SCTP stack. A blind attacker may be able to kill an existing SCTP association through invalid chunks if the attacker knows the IP-addresses and port numbers being used an...
How severe is CVE-2021-3772?
CVE-2021-3772 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-3772?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Redhat Enterprise Linux, Debian Debian Linux, Oracle Communications Cloud Native Core Binding Support Function, Oracle Communications Cloud Native Core Network Exposure Function.