Executive brief
A vulnerability was identified in the Linux kernel's implementation of the SCTP networking protocol. This flaw could allow a local user to cause a system crash or unpredictable behavior due to the way the system handles certain network address data. This primarily impacts the availability of the affected system.
Technical details
A 'use of uninitialized resource' vulnerability (CWE-908) exists in the Linux kernel SCTP (Stream Control Transmission Protocol) implementation. The function sctp_v6_from_sk() failed to properly initialize the sin6_scope_id and sin6_flowinfo fields when creating IPv6 address structures. This leads to an uninitialized-value bug in __sctp_v6_cmp_addr during address comparison operations, such as when starting a listen socket or resolving bind address conflicts. An attacker with local access could exploit this to trigger undefined behavior or a kernel panic (Denial of Service). The issue has been resolved by explicitly clearing these fields in the affected function across multiple stable kernel branches.
Affected products
- Linux Linux Kernel 2.6.12-rc2 to 6.16.5
Timeline
- 2025-08-26: patched: Initial patch authored by Eric Dumazet
- 2025-09-16: disclosed: CVE published
References
- https://git.kernel.org/stable/c/17d6c7747045e9b802c2f5dfaba260d309d831ae
- https://git.kernel.org/stable/c/1bbc0c02aea1f1c405bd1271466889c25a1fe01b
- https://git.kernel.org/stable/c/2e8750469242cad8f01f320131fd5a6f540dbb99
- https://git.kernel.org/stable/c/45e4b36593edffb7bbee5828ae820bc10a9fa0f3
- https://git.kernel.org/stable/c/463aa96fca6209bb205f49f7deea3817d7ddaa3a
- https://git.kernel.org/stable/c/65b4693d8bab5370cfcb44a275b4d8dcb06e56bf
- https://git.kernel.org/stable/c/9546934c2054bba1bd605c44e936619159a34027