Impact
In the Linux kernel’s SCTP module, improper validation at the cookie trust boundary allows a forged cookie to overrun internal buffers during key-vector construction. The flaw can cause out-of-bounds reads and a 32‑byte write past a zero-length buffer, providing a local privilege escalation primitive.
Affected Systems
All Linux kernel releases that include the SCTP module before the supplied fix are affected. The issue exists in the socket layer handling SCTP cookies; any host running a kernel with SCTP enabled, regardless of distribution, is vulnerable.
Risk and Exploitability
The base CVSS score is 9.8, indicating critical severity. The EPSS score is <1%, suggesting a very low probability of exploitation, though precise likelihood cannot be quantified. The vulnerability is not listed in CISA KEV. The flaw can be triggered by sending crafted SCTP COOKIE_ECHO messages; however, the description does not explicitly confirm network delivery as the attack vector, so this is inferred from the context.
OpenCVE Enrichment