Linux Kernel SCTP Constant-Time MAC Comparison Vulnerability

Vulnerability

A vulnerability in the Linux kernel's handling of SCTP (Stream Control Transmission Protocol) has been addressed. The issue was related to the comparison of Message Authentication Codes (MACs) in a manner that could be exploited through timing attacks. This vulnerability was present in the SCTP implementation within the kernel.

Impact

The vulnerability could lead to timing attacks, where an attacker could potentially infer information based on the time taken to perform cryptographic operations, allowing them to manipulate or predict behavior in a way that could be exploited.

Reproduction

The vulnerability could be reproduced by sending SCTP packets that require authentication. The kernel's SCTP implementation would process these packets and compare digests using a non-constant-time method, creating a timing discrepancy that could be measured and exploited.

Remediation

Users can upgrade to the latest version of the Linux kernel where this vulnerability has been fixed. Instructions for upgrading the kernel can be found in the official Linux kernel documentation.

Added: Nov 12, 2025, 10:30 PM
Updated: Nov 12, 2025, 10:30 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
2.5
exploitability
5.7
remediation
7.7
relevance
0.9
threat
4.8
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.