Linux Kernel SCTP Sysctl UDP Port Vulnerability Leading to Null Pointer Dereference

Vulnerability

A vulnerability in the Linux kernel's SCTP (Stream Control Transmission Protocol) implementation has been addressed. The issue arose from the sysctl UDP port handling, which improperly used the 'current' context to access network namespace information. This approach could lead to inconsistencies and potential null pointer dereferences, particularly when the current task is exiting. The vulnerability was identified by syzbot while using the acct system call.

Impact

Exploitation of this vulnerability could lead to a null pointer dereference, causing a kernel crash.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
2.5
exploitability
5.3
remediation
0.0
relevance
0.0
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.