VYPR
Unrated severityNVD Advisory· Published Jan 11, 2011· Updated Apr 29, 2026

CVE-2010-4526

CVE-2010-4526

Description

Race condition in the sctp_icmp_proto_unreachable function in net/sctp/input.c in Linux kernel 2.6.11-rc2 through 2.6.33 allows remote attackers to cause a denial of service (panic) via an ICMP unreachable message to a socket that is already locked by a user, which causes the socket to be freed and triggers list corruption, related to the sctp_wait_for_connect function.

Affected products

8
  • Linux/Kernel5 versions
    cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*+ 4 more
    • cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*range: >=2.6.11.1,<=2.6.33
    • cpe:2.3:o:linux:linux_kernel:2.6.11:rc2:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:2.6.11:rc3:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:2.6.11:rc4:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:2.6.11:rc5:*:*:*:*:*:*
  • cpe:2.3:o:redhat:enterprise_mrg:1.0:*:*:*:*:*:*:*
  • VMware/Esx2 versions
    cpe:2.3:o:vmware:esx:4.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:vmware:esx:4.0:*:*:*:*:*:*:*
    • cpe:2.3:o:vmware:esx:4.1:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

11

News mentions

0

No linked articles in our index yet.