CVE-2014-0101: Canonical Ubuntu Linux

High severity, CVSS 7.8. EPSS: 7.2% chance of exploitation in the next 30 days.

The sctp_sf_do_5_1D_ce function in net/sctp/sm_statefuns.c in the Linux kernel through 3.13.6 does not validate certain auth_enable and auth_capable fields before making an sctp_sf_authenticate call, which allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) via an SCTP handshake with a modified INIT chunk and a crafted AUTH chunk before a COOKIE_ECHO chunk.

Affected products

  • Canonical Ubuntu Linux: version 10.04 only
  • F5 BIG-IP Access Policy Manager: from 11.1.0, up to and including 11.5.3
  • F5 BIG-IP Advanced Firewall Manager: from 11.3.0, up to and including 11.5.3
  • F5 BIG-IP Analytics: from 11.1.0, up to and including 11.5.3
  • F5 BIG-IP Application Acceleration Manager: from 11.4.0, up to and including 11.5.3
  • F5 BIG-IP Application Security Manager: from 11.1.0, up to and including 11.5.3
  • F5 BIG-IP Edge Gateway: from 11.1.0, up to and including 11.3.0
  • F5 BIG-IP Enterprise Manager: from 2.1.0, up to and including 2.3.0; from 3.0.0, up to and including 3.1.1
  • F5 BIG-IP Global Traffic Manager: from 11.1.0, up to and including 11.5.3
  • F5 BIG-IP Link Controller: from 11.1.0, up to and including 11.5.3
  • F5 BIG-IP Local Traffic Manager: from 11.1.0, up to and including 11.5.3
  • F5 BIG-IP Policy Enforcement Manager: from 11.3.0, up to and including 11.5.3
  • F5 BIG-IP Protocol Security Module: from 11.1.0, up to and including 11.4.1
  • F5 BIG-IP WAN Optimization Manager: from 11.1.0, up to and including 11.3.0
  • F5 BIG-IP Webaccelerator: from 11.1.0, up to and including 11.3.0
  • F5 BIG-IQ ADC: version 4.5.0 only
  • F5 BIG-IQ Centralized Management: version 4.6.0 only
  • F5 BIG-IQ Cloud: from 4.0.0, up to and including 4.5.0
  • F5 BIG-IQ Device: from 4.2.0, up to and including 4.5.0
  • F5 BIG-IQ Security: from 4.0.0, up to and including 4.5.0
  • Linux Linux Kernel: from 2.6.24, before 3.2.56 (fixed in 3.2.56); from 3.3, before 3.4.84 (fixed in 3.4.84); from 3.5, before 3.10.34 (fixed in 3.10.34); from 3.11, before 3.12.15 (fixed in 3.12.15); from 3.13, before 3.13.7 (fixed in 3.13.7)
  • Red Hat Enterprise Linux Desktop: version 6.0 only
  • Red Hat Enterprise Linux Eus: version 6.3 only; version 6.4 only; version 6.5 only
  • Red Hat Enterprise Linux Server: version 6.0 only
  • Red Hat Enterprise Linux Server Aus: version 6.4 only; version 6.5 only
  • and 2 more

Published 2014-03-11. Last modified 2026-06-17.