Vulnerability identifier: #VU94464
Vulnerability risk: Low
CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID:
CWE-ID:
CWE-908
Exploitation vector: Local
Exploit availability: No
Vulnerable software:
Linux kernel
Operating systems & Components /
Operating system
Vendor: Linux Foundation
Description
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to use of uninitialized resource within the inet_diag_msg_sctpasoc_fill() and inet_sctp_diag_fill() functions in net/sctp/sctp_diag.c. A local user can perform a denial of service (DoS) attack.
Mitigation
Install update from vendor's website.
Vulnerable software versions
Linux kernel: All versions
External links
https://git.kernel.org/stable/c/3fc0fd724d199e061432b66a8d85b7d48fe485f7
https://git.kernel.org/stable/c/41a2864cf719c17294f417726edd411643462ab8
https://git.kernel.org/stable/c/2d8fa3fdf4542a2174a72d92018f488d65d848c5
https://git.kernel.org/stable/c/bbf59d7ae558940cfa2b36a287fd1e88d83f89f8
https://git.kernel.org/stable/c/b7e4d9ba2ddb78801488b4c623875b81fb46b545
https://git.kernel.org/stable/c/1502f15b9f29c41883a6139f2923523873282a83
https://git.kernel.org/stable/c/d828b0fe6631f3ae8709ac9a10c77c5836c76a08
https://git.kernel.org/stable/c/633593a808980f82d251d0ca89730d8bb8b0220c
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.