Impact
The flaw occurs when an SCTP stream reconfiguration request has been queued but not yet transmitted and the completion routine deletes the reconfiguration timer. The code then dereferences a transport pointer that is NULL, causing a kernel panic. This results in an immediate loss of availability for the affected host, consistent with a denial‑of‑service condition. The weakness is a classic null pointer dereference (CWE-476).
Affected Systems
All Linux kernel installations that have SCTP support enabled – either compiled into the kernel or loaded as a module – are potentially affected. No specific kernel version is listed; any kernel build with generic SCTP code prior to the patched commit is vulnerable regardless of distribution.
Risk and Exploitability
With a CVSS score of 7.5 the vulnerability is classified as high severity. The EPSS score of less than 1 % indicates that exploitation is not widespread, and the vulnerability is not listed in the CISA KEV catalog. Attackers can trigger the fault locally by removing the last IP address from an association without sending an ASCONF update, or remotely by sending crafted SCTP reset messages that are received by a vulnerable host. The result is a kernel panic and disruption of service. Based on the description, it is inferred that the attack can be launched from either local or remote contexts, with the remote scenario requiring the ability to send SCTP packets to the target.
OpenCVE Enrichment
Debian DSA