AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2008-3792

HIGH · CVSS 7.1 EPSS 2.67%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2008-09-03 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.1. It affects Linux. It may lead to a denial-of-service condition.

CVE
CVE-2008-3792
Severity
HIGH
CVSS
7.1
EPSS
2.67%
Linux

Original NVD Description

net/sctp/socket.c in the Stream Control Transmission Protocol (sctp) implementation in the Linux kernel before 2.6.26.4 does not verify that the SCTP-AUTH extension is enabled before proceeding with SCTP-AUTH API functions, which allows attackers to cause a denial of service (NULL pointer dereference and panic) via vectors that result in calls to (1) sctp_setsockopt_auth_chunk, (2) sctp_setsockopt_hmac_ident, (3) sctp_setsockopt_auth_key, (4) sctp_setsockopt_active_key, (5) sctp_setsockopt_del_key, (6) sctp_getsockopt_maxburst, (7) sctp_getsockopt_active_key, (8) sctp_getsockopt_peer_auth_chunks, or (9) sctp_getsockopt_local_auth_chunks.