Impact
The Linux kernel SCTP stack has a use‑after‑free bug that can be triggered by sending a, SHUTDOWN, or SHUTDOWN ACK chunk. The bug occurs when the endpoint processes a packet after its association has been freed, writing to freed memory and potentially corrupting kernel state. In the worst case an attacker can gain kernel code execution or cause a system crash by manipulating the freed data.
Affected Systems
Affected systems are Linux kernel installations that include the SCTP protocol stack, whether built‑in or via the sctp module. Systems running any Linux kernel version that contains the SCTP implementation prior to the fix are susceptible.
Risk and Exploitability
The CVSS score of 9.8 classifies the vulnerability as Critical. Its EPSS score is listed as < 1 %, indicating a low probability of exploitation, and it is not present in the CISA KEV catalog. The likely attack vector is remote: an attacker can send the malicious SCTP packets over the network to the target host. Successful exploitation would result in denial of service through a kernel crash and, if the attacker can influence the freed memory contents, arbitrary code execution at kernel level. The vulnerability requires that the attacker bundles specific SCTP chunks in a single packet, connection.
OpenCVE Enrichment
Debian DSA