Impact
A race condition in the Linux kernel SCTP stack allows an authenticated ASCONF DEL‑IP operation to remove a transport while a pending data chunk still references it, causing the transport to be freed before the chunk is processed. The stale reference is later dereferenced during delayed SACK processing, leading to a kernel crash and rendering the host unavailable. The vulnerability is identified as a resource management error consistent with CWE‑825.
Affected Systems
Linux kernels with SCTP support that have not yet incorporated commit 03a9d10ecf71f54b2af8020935f2033d4a132be5 are affected. This includes most distributions that ship with SCTP enabled in the kernel and have not applied the fix.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical risk to system availability. The EPSS score of less than 1% suggests that verified exploitation is considered unlikely, but not impossible. The flaw is not cataloged in CISA KEV, and it requires an attacker with the privilege to issue an ASCONF DEL‑IP command on an SCTP association, which would terminate the operating system’s kernel, causing service disruption; no known remote exploitation vectors or public exploits are documented.
OpenCVE Enrichment
Debian DSA