2021-09-06 07:00:55 +00:00
{
2023-02-02 21:00:39 +00:00
"data_version" : "4.0" ,
2021-09-06 07:00:55 +00:00
"data_type" : "CVE" ,
"data_format" : "MITRE" ,
"CVE_data_meta" : {
"ID" : "CVE-2021-3772" ,
2022-03-02 23:01:20 +00:00
"ASSIGNER" : "secalert@redhat.com" ,
"STATE" : "PUBLIC"
} ,
2023-02-02 21:00:39 +00:00
"description" : {
"description_data" : [
{
"lang" : "eng" ,
"value" : "A flaw was found in the Linux SCTP stack. A blind attacker may be able to kill an existing SCTP association through invalid chunks if the attacker knows the IP-addresses and port numbers being used and the attacker can send packets with spoofed IP addresses."
}
]
} ,
"problemtype" : {
"problemtype_data" : [
{
"description" : [
{
"lang" : "eng" ,
"value" : "Improper Validation of Integrity Check Value" ,
"cweId" : "CWE-354"
}
]
}
]
} ,
2022-03-02 23:01:20 +00:00
"affects" : {
"vendor" : {
"vendor_data" : [
{
2023-02-02 21:00:39 +00:00
"vendor_name" : "Red Hat" ,
2022-03-02 23:01:20 +00:00
"product" : {
"product_data" : [
{
2023-02-02 21:00:39 +00:00
"product_name" : "Red Hat Enterprise Linux 8" ,
2022-03-02 23:01:20 +00:00
"version" : {
"version_data" : [
{
2023-02-02 21:00:39 +00:00
"version_value" : "0:4.18.0-372.9.1.rt7.166.el8" ,
"version_affected" : "!"
} ,
{
"version_value" : "0:4.18.0-372.9.1.el8" ,
"version_affected" : "!"
2022-03-02 23:01:20 +00:00
}
]
}
}
]
}
}
]
}
} ,
"references" : {
"reference_data" : [
{
2023-02-02 21:00:39 +00:00
"url" : "https://ubuntu.com/security/CVE-2021-3772" ,
2022-03-02 23:01:20 +00:00
"refsource" : "MISC" ,
2023-02-02 21:00:39 +00:00
"name" : "https://ubuntu.com/security/CVE-2021-3772"
2022-03-02 23:01:20 +00:00
} ,
{
2023-02-02 21:00:39 +00:00
"url" : "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=32f8807a48ae55be0e76880cfe8607a18b5bb0df" ,
2022-03-02 23:01:20 +00:00
"refsource" : "MISC" ,
2023-02-02 21:00:39 +00:00
"name" : "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=32f8807a48ae55be0e76880cfe8607a18b5bb0df"
2022-03-02 23:01:20 +00:00
} ,
{
2023-02-02 21:00:39 +00:00
"url" : "https://github.com/torvalds/linux/commit/32f8807a48ae55be0e76880cfe8607a18b5bb0df" ,
2022-03-02 23:01:20 +00:00
"refsource" : "MISC" ,
2023-02-02 21:00:39 +00:00
"name" : "https://github.com/torvalds/linux/commit/32f8807a48ae55be0e76880cfe8607a18b5bb0df"
2022-03-02 23:01:20 +00:00
} ,
{
2023-02-02 21:00:39 +00:00
"url" : "https://www.oracle.com/security-alerts/cpujul2022.html" ,
2022-03-02 23:01:20 +00:00
"refsource" : "MISC" ,
2023-02-02 21:00:39 +00:00
"name" : "https://www.oracle.com/security-alerts/cpujul2022.html"
2022-03-10 17:28:38 +00:00
} ,
{
2023-02-02 21:00:39 +00:00
"url" : "https://access.redhat.com/errata/RHSA-2022:1975" ,
"refsource" : "MISC" ,
"name" : "https://access.redhat.com/errata/RHSA-2022:1975"
2022-03-10 17:28:38 +00:00
} ,
{
2023-02-02 21:00:39 +00:00
"url" : "https://access.redhat.com/errata/RHSA-2022:1988" ,
"refsource" : "MISC" ,
"name" : "https://access.redhat.com/errata/RHSA-2022:1988"
2022-07-19 14:38:32 -07:00
} ,
{
2023-02-02 21:00:39 +00:00
"url" : "https://lists.debian.org/debian-lts-announce/2022/03/msg00012.html" ,
2022-07-25 19:01:27 +00:00
"refsource" : "MISC" ,
2023-02-02 21:00:39 +00:00
"name" : "https://lists.debian.org/debian-lts-announce/2022/03/msg00012.html"
2022-10-07 14:00:35 +00:00
} ,
{
2023-02-02 21:00:39 +00:00
"url" : "https://www.debian.org/security/2022/dsa-5096" ,
"refsource" : "MISC" ,
"name" : "https://www.debian.org/security/2022/dsa-5096"
} ,
{
"url" : "https://access.redhat.com/security/cve/CVE-2021-3772" ,
"refsource" : "MISC" ,
"name" : "https://access.redhat.com/security/cve/CVE-2021-3772"
} ,
{
"url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2000694" ,
"refsource" : "MISC" ,
"name" : "https://bugzilla.redhat.com/show_bug.cgi?id=2000694"
} ,
{
"url" : "https://security.netapp.com/advisory/ntap-20221007-0001/" ,
"refsource" : "MISC" ,
"name" : "https://security.netapp.com/advisory/ntap-20221007-0001/"
2022-03-02 23:01:20 +00:00
}
]
2021-09-06 07:00:55 +00:00
} ,
2023-02-02 21:00:39 +00:00
"work_around" : [
{
"lang" : "en" ,
"value" : "As the SCTP module will be auto-loaded when required, its use can be disabled by preventing the module from loading with the following instructions:\nif\n# echo \"install sctp /bin/true\" >> /etc/modprobe.d/disable-sctp.conf\n\nThe system will need to be restarted if the SCTP modules are loaded. In most circumstances, the SCTP kernel modules will be unable to be unloaded while any network interfaces are active and the protocol is in use.\n\nIf the system requires this module to work correctly, this mitigation may not be suitable.\n\nIf you need further assistance, see KCS article https://access.redhat.com/solutions/41278 or contact Red Hat Global Support Services."
}
] ,
"impact" : {
"cvss" : [
2021-09-06 07:00:55 +00:00
{
2023-02-02 21:00:39 +00:00
"attackComplexity" : "HIGH" ,
"attackVector" : "NETWORK" ,
"availabilityImpact" : "HIGH" ,
"baseScore" : 5.9 ,
"baseSeverity" : "MEDIUM" ,
"confidentialityImpact" : "NONE" ,
"integrityImpact" : "NONE" ,
"privilegesRequired" : "NONE" ,
"scope" : "UNCHANGED" ,
"userInteraction" : "NONE" ,
"vectorString" : "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" ,
"version" : "3.1"
2021-09-06 07:00:55 +00:00
}
]
}
}