CVE-2006-2275 describes a denial-of-service vulnerability in Linux SCTP (lksctp) versions prior to 2.6.17, affecting Canonical and lksctp implementations. Remote attackers can trigger a deadlock by sending a high volume of small messages, overwhelming the receiver's buffer. This vulnerability carries a CVSS score of 7.5 (HIGH), indicating a network-based attack with low complexity leading to high availability impact. There is no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage for this older CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.6.17CPE matchmatch criteria | cpe:2.3:a:lksctp:stream_control_transmission_protocol:*:*:*:*:*:*:*:* | ||
5.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:5.04:*:*:*:*:*:*:* | ||
5.10CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:5.10:*:*:*:*:*:*:* | ||
6.06CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.