Linux Kernel SCTP Sysctl RTO Minimum/Maximum Vulnerability

Vulnerability

A vulnerability in the Linux kernel's SCTP (Stream Control Transmission Protocol) sysctl interface for minimum and maximum retransmission timeouts has been addressed. The issue arose from using the 'net' structure via 'current', which can lead to inconsistencies and potential null pointer dereferences. This vulnerability was identified by syzbot while using the acct system call.

Impact

Exploitation of this vulnerability could lead to a null pointer dereference, causing a kernel crash.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
2.5
exploitability
5.3
remediation
0.0
relevance
0.0
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.