Junglewise Threat Intelligence

CVE-2024-50299: Linux Kernel uninitialized-value access in SCTP sctp_sf_ootb

CVE-2024-50299 · Severity: medium · CVSS 5.5 · Published 2024-11-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's networking component could allow a local user to crash the system. The issue occurs when the system processes specific types of network traffic (SCTP) that are not properly validated. This can lead to a denial-of-service condition, impacting the availability of the affected server or device.

Technical details

A vulnerability exists in the Linux kernel's SCTP (Stream Control Transmission Protocol) implementation within the sctp_sf_ootb() function in net/sctp/sm_statefuns.c. The root cause is a lack of proper size validation when walking through SCTP chunks, which can lead to an uninitialized-value access (CWE-908) and a subsequent kernel crash. An attacker with local access could exploit this to cause a denial-of-service. The fix involves ensuring the chunk header size is correctly validated against the remaining buffer length during iteration. Patches have been released for multiple stable kernel branches including 4.19, 5.4, 5.10, 5.15, 6.1, 6.6, and 6.11.

Affected products

  • Linux Linux Kernel 2.6.12 to 4.19.324, 4.20 to 5.4.286, 5.5 to 5.10.230, 5.11 to 5.15.172, 5.16 to 6.1.117, 6.2 to 6.6.61, 6.7 to 6.11.8

Timeline

  • 2024-10-29: other: Patch authored
  • 2024-11-19: advisory: CVE published

References

Related threats