Impact
The Linux kernel’s SCTP stack contains a flaw where duplicate RECONF responses can decrement the stream->outcnt counter twice, potentially causing an integer underflow. When the counter wraps below zero, kernel state can become inconsistent, which may result in crashes, memory corruption, or other unpredictable behavior. Based on the description, an attacker could trigger this underflow by sending SCTP packets that provoke duplicate RECONF responses; the likely attack vector is remote over the network.
Affected Systems
All distributions’ Linux kernels that include the default SCTP implementation and have not incorporated the patch commits referenced in the advisory (for example, 2d867663…, 3faf13aff…, 8320cbd81…, d02a5794…). These are common across vendors such as Red Hat, Ubuntu, Debian, Fedora, CentOS, and others.
Risk and Exploitability
The CVSS score of 7.5 rates this flaw as high severity. The EPSS score of less than 1 % indicates a very low but nonzero probability of exploitation at the current time, and the vulnerability is not listed in the CISA KEV catalog. Even with low exploitation likelihood, the impact on kernel stability warrants timely remediation.
OpenCVE Enrichment
Debian DSA