CVE-2014-3688: Linux Kernel

Medium severity, CVSS 5.0. EPSS: 5.9% chance of exploitation in the next 30 days.

The SCTP implementation in the Linux kernel before 3.17.4 allows remote attackers to cause a denial of service (memory consumption) by triggering a large number of chunks in an association's output queue, as demonstrated by ASCONF probes, related to net/sctp/inqueue.c and net/sctp/sm_statefuns.c.

Affected products

  • Linux Linux Kernel: up to and including 3.17.3; version 3.0 only; version 3.0.1 only; version 3.0.2 only; version 3.0.3 only; version 3.0.4 only; …

Published 2014-11-30. Last modified 2026-06-17.