CVE-2017-5986
published 2017-02-18CVE-2017-5986: Race condition in the sctp_wait_for_sndbuf function in net/sctp/socket.c in the Linux kernel before 4.9.11 allows local users to cause a denial of service…
PriorityP418medium5.5CVSS 3.0
AVLACLPRNUIRSUCNINAH
EPSS
1.16%
64.2th percentile
Race condition in the sctp_wait_for_sndbuf function in net/sctp/socket.c in the Linux kernel before 4.9.11 allows local users to cause a denial of service (assertion failure and panic) via a multithreaded application that peels off an association in a certain buffer-full state.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.9.13-1 (bookworm) | linux 4.9.13-1 (bookworm) |
| debian | linux | < linux 4.9.10-1 (bookworm) | linux 4.9.10-1 (bookworm) |
| linux | linux_kernel | <= 4.10 | — |
| linux | linux_kernel | <= 4.9.11 | — |
| linux | linux_kernel | >= 0 < 4.9.13-1 | 4.9.13-1 |
| linux | linux_kernel | >= 0 < 4.9.10-1 | 4.9.10-1 |
| linux | linux_kernel | >= 0 < 4.9.13-1 | 4.9.13-1 |
| linux | linux_kernel | >= 0 < 4.9.10-1 | 4.9.10-1 |
| linux | linux_kernel | >= 0 < 4.9.13-1 | 4.9.13-1 |
| linux | linux_kernel | >= 0 < 4.9.10-1 | 4.9.10-1 |
| linux | linux_kernel | >= 0 < 4.9.13-1 | 4.9.13-1 |
| linux | linux_kernel | >= 0 < 4.9.10-1 | 4.9.10-1 |
| linux | linux_kernel | >= 0 < 4.4.0-75.96 | 4.4.0-75.96 |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8whq-7xh2-jxhw: net/sctp/socket
ghsa_unreviewed·2022-05-17·CVSS 5.5
CVE-2017-6353 [MEDIUM] CWE-415 GHSA-8whq-7xh2-jxhw: net/sctp/socket
net/sctp/socket.c in the Linux kernel through 4.10.1 does not properly restrict association peel-off operations during certain wait states, which allows local users to cause a denial of service (invalid unlock and double free) via a multithreaded application. NOTE: this vulnerability exists because of an incorrect fix for CVE-2017-5986.
GHSA
GHSA-93r7-h3jv-xg2q: Race condition in the sctp_wait_for_sndbuf function in net/sctp/socket
ghsa_unreviewed·2022-05-13
CVE-2017-5986 [HIGH] CWE-362 GHSA-93r7-h3jv-xg2q: Race condition in the sctp_wait_for_sndbuf function in net/sctp/socket
Race condition in the sctp_wait_for_sndbuf function in net/sctp/socket.c in the Linux kernel before 4.9.11 allows local users to cause a denial of service (assertion failure and panic) via a multithreaded application that peels off an association in a certain buffer-full state.
OSV
linux-lts-xenial vulnerabilities
osv·2017-04-25·CVSS 7.8
CVE-2017-7374 [HIGH] linux-lts-xenial vulnerabilities
linux-lts-xenial vulnerabilities
USN-3265-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 LTS.
It was discovered that a use-after-free flaw existed in the filesystem
encryption subsystem in the Linux kernel. A local attacker could use this
to cause a denial of service (system crash). (CVE-2017-7374)
Andrey Konovalov discovered an out-of-bounds access in the IPv6 Generic
Routing Encapsulation (GRE) tunneling implementation in the Linux kernel.
An attacker could use this to possibly expose sensitive information.
(CVE-2017-5897)
Andrey Konovalov discovered that the IPv4 implementation in the Linux
kernel did not properly handle invalid IP o
OSV
linux, linux-aws, linux-gke, linux-raspi2, linux-snapdragon vulnerabilities
osv·2017-04-25·CVSS 7.8
CVE-2017-7374 [HIGH] linux, linux-aws, linux-gke, linux-raspi2, linux-snapdragon vulnerabilities
linux, linux-aws, linux-gke, linux-raspi2, linux-snapdragon vulnerabilities
It was discovered that a use-after-free flaw existed in the filesystem
encryption subsystem in the Linux kernel. A local attacker could use this
to cause a denial of service (system crash). (CVE-2017-7374)
Andrey Konovalov discovered an out-of-bounds access in the IPv6 Generic
Routing Encapsulation (GRE) tunneling implementation in the Linux kernel.
An attacker could use this to possibly expose sensitive information.
(CVE-2017-5897)
Andrey Konovalov discovered that the IPv4 implementation in the Linux
kernel did not properly handle invalid IP options in some situations. An
attacker could use this to cause a denial of service or possibly execute
arbitrary code. (CVE-2017-5970)
Gareth Evans discovered that the sh
OSV
CVE-2017-6353: net/sctp/socket
osv·2017-03-01·CVSS 5.5
CVE-2017-6353 [MEDIUM] CVE-2017-6353: net/sctp/socket
net/sctp/socket.c in the Linux kernel through 4.10.1 does not properly restrict association peel-off operations during certain wait states, which allows local users to cause a denial of service (invalid unlock and double free) via a multithreaded application. NOTE: this vulnerability exists because of an incorrect fix for CVE-2017-5986.
OSV
CVE-2017-5986: Race condition in the sctp_wait_for_sndbuf function in net/sctp/socket
osv·2017-02-18·CVSS 5.5
CVE-2017-5986 [MEDIUM] CVE-2017-5986: Race condition in the sctp_wait_for_sndbuf function in net/sctp/socket
Race condition in the sctp_wait_for_sndbuf function in net/sctp/socket.c in the Linux kernel before 4.9.11 allows local users to cause a denial of service (assertion failure and panic) via a multithreaded application that peels off an association in a certain buffer-full state.
Ubuntu
Linux kernel vulnerability
vendor_ubuntu·2017-04-25
CVE-2017-5986 Linux kernel vulnerability
Title: Linux kernel vulnerability
Summary: The system could be made to crash under certain conditions.
Alexander Popov discovered that a race condition existed in the Stream
Control Transmission Protocol (SCTP) implementation in the Linux kernel. A
local attacker could use this to cause a denial of service (system crash).
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard
Ubuntu
Linux kernel (HWE) vulnerability
vendor_ubuntu·2017-04-25
CVE-2017-5986 Linux kernel (HWE) vulnerability
Title: Linux kernel (HWE) vulnerability
Summary: The system could be made to crash under certain conditions.
USN-3266-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.10.
This update provides the corresponding updates for the Linux Hardware
Enablement (HWE) kernel from Ubuntu 16.10 for Ubuntu 16.04 LTS.
Alexander Popov discovered that a race condition existed in the Stream
Control Transmission Protocol (SCTP) implementation in the Linux kernel. A
local attacker could use this to cause a denial of service (system crash).
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2017-04-25·CVSS 7.8
CVE-2017-5669 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that a use-after-free flaw existed in the filesystem
encryption subsystem in the Linux kernel. A local attacker could use this
to cause a denial of service (system crash). (CVE-2017-7374)
Andrey Konovalov discovered an out-of-bounds access in the IPv6 Generic
Routing Encapsulation (GRE) tunneling implementation in the Linux kernel.
An attacker could use this to possibly expose sensitive information.
(CVE-2017-5897)
Andrey Konovalov discovered that the IPv4 implementation in the Linux
kernel did not properly handle invalid IP options in some situations. An
attacker could use this to cause a denial of service or possibly execute
arbitrary code. (CVE-2017-5970)
Gareth Evans di
Ubuntu
Linux kernel (Xenial HWE) vulnerabilities
vendor_ubuntu·2017-04-25·CVSS 7.8
CVE-2017-5669 [HIGH] Linux kernel (Xenial HWE) vulnerabilities
Title: Linux kernel (Xenial HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
USN-3265-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 LTS.
It was discovered that a use-after-free flaw existed in the filesystem
encryption subsystem in the Linux kernel. A local attacker could use this
to cause a denial of service (system crash). (CVE-2017-7374)
Andrey Konovalov discovered an out-of-bounds access in the IPv6 Generic
Routing Encapsulation (GRE) tunneling implementation in the Linux kernel.
An attacker could use this to possibly expose sensitive information.
(CVE-2017-5897)
Andrey Konovalov discovered that the
Ubuntu
Linux kernel (Trusty HWE) vulnerability
vendor_ubuntu·2017-04-24
CVE-2017-5986 Linux kernel (Trusty HWE) vulnerability
Title: Linux kernel (Trusty HWE) vulnerability
Summary: The system could be made to crash under certain conditions.
USN-3264-1 fixed vulnerabilities in the Linux kernel for Ubuntu 14.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 14.04 LTS for Ubuntu
12.04 LTS.
Alexander Popov discovered that a race condition existed in the Stream
Control Transmission Protocol (SCTP) implementation in the Linux kernel. A
local attacker could use this to cause a denial of service (system crash).
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile
Red Hat
kernel: Possible double free in stcp_sendmsg() (incorrect fix for CVE-2017-5986)
vendor_redhat·2017-02-23·CVSS 5.5
CVE-2017-6353 [MEDIUM] CWE-416 kernel: Possible double free in stcp_sendmsg() (incorrect fix for CVE-2017-5986)
kernel: Possible double free in stcp_sendmsg() (incorrect fix for CVE-2017-5986)
net/sctp/socket.c in the Linux kernel through 4.10.1 does not properly restrict association peel-off operations during certain wait states, which allows local users to cause a denial of service (invalid unlock and double free) via a multithreaded application. NOTE: this vulnerability exists because of an incorrect fix for CVE-2017-5986.
It was found that the code in net/sctp/socket.c in the Linux kernel through 4.10.1 does not properly restrict association peel-off operations during certain wait states, which allows local users to cause a denial of service (invalid unlock and double free) via a multithreaded application. This vulnerability was introduced by CVE-2017-5986 fix (commit 2dcab5984841).
Statement
Red Hat
kernel: Reachable BUG_ON from userspace in sctp_wait_for_sndbuf
vendor_redhat·2017-02-06·CVSS 5.5
CVE-2017-5986 [MEDIUM] CWE-617 kernel: Reachable BUG_ON from userspace in sctp_wait_for_sndbuf
kernel: Reachable BUG_ON from userspace in sctp_wait_for_sndbuf
Race condition in the sctp_wait_for_sndbuf function in net/sctp/socket.c in the Linux kernel before 4.9.11 allows local users to cause a denial of service (assertion failure and panic) via a multithreaded application that peels off an association in a certain buffer-full state.
It was reported that with Linux kernel, earlier than version v4.10-rc8, an application may trigger a BUG_ON in sctp_wait_for_sndbuf if the socket tx buffer is full, a thread is waiting on it to queue more data, and meanwhile another thread peels off the association being used by the first thread.
Statement: This issue affects the Linux kernel packages as shipped with Red Hat Enterprise Linux 5, 6 and MRG-2. This has been rated as having Moderate secu
Debian
CVE-2017-6353: linux - net/sctp/socket.c in the Linux kernel through 4.10.1 does not properly restrict ...
vendor_debian·2017·CVSS 5.5
CVE-2017-6353 [MEDIUM] CVE-2017-6353: linux - net/sctp/socket.c in the Linux kernel through 4.10.1 does not properly restrict ...
net/sctp/socket.c in the Linux kernel through 4.10.1 does not properly restrict association peel-off operations during certain wait states, which allows local users to cause a denial of service (invalid unlock and double free) via a multithreaded application. NOTE: this vulnerability exists because of an incorrect fix for CVE-2017-5986.
Scope: local
bookworm: resolved (fixed in 4.9.13-1)
bullseye: resolved (fixed in 4.9.13-1)
forky: resolved (fixed in 4.9.13-1)
sid: resolved (fixed in 4.9.13-1)
trixie: resolved (fixed in 4.9.13-1)
Debian
CVE-2017-5986: linux - Race condition in the sctp_wait_for_sndbuf function in net/sctp/socket.c in the ...
vendor_debian·2017·CVSS 5.5
CVE-2017-5986 [MEDIUM] CVE-2017-5986: linux - Race condition in the sctp_wait_for_sndbuf function in net/sctp/socket.c in the ...
Race condition in the sctp_wait_for_sndbuf function in net/sctp/socket.c in the Linux kernel before 4.9.11 allows local users to cause a denial of service (assertion failure and panic) via a multithreaded application that peels off an association in a certain buffer-full state.
Scope: local
bookworm: resolved (fixed in 4.9.10-1)
bullseye: resolved (fixed in 4.9.10-1)
forky: resolved (fixed in 4.9.10-1)
sid: resolved (fixed in 4.9.10-1)
trixie: resolved (fixed in 4.9.10-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-6353 kernel: Possible double free in stcp_sendmsg() (incorrect fix for CVE-2017-5986)
bugzilla·2017-03-03·CVSS 5.5
CVE-2017-6353 [MEDIUM] CVE-2017-6353 kernel: Possible double free in stcp_sendmsg() (incorrect fix for CVE-2017-5986)
CVE-2017-6353 kernel: Possible double free in stcp_sendmsg() (incorrect fix for CVE-2017-5986)
net/sctp/socket.c in the Linux kernel through 4.10.1 does not properly restrict association peel-off operations during certain wait states, which allows local users to cause a denial of service (invalid unlock and double free) via a multithreaded application.
This vulnerability was introduced by CVE-2017-5986 fix (commit 2dcab5984841).
Upstream patch:
https://github.com/torvalds/linux/commit/dfcb9f4f99f1e9a49e43398a7bfbf56927544af1
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1428910]
---
Statement:
This issue does not affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 5, 6, 7 and MRG-2, as the problem code is not presented in
Bugzilla
CVE-2017-6353 kernel: Possible double free in stcp_sendmsg() (incorrect fix for CVE-2017-5986) [fedora-all]
bugzilla·2017-03-03·CVSS 5.5
CVE-2017-6353 [MEDIUM] CVE-2017-6353 kernel: Possible double free in stcp_sendmsg() (incorrect fix for CVE-2017-5986) [fedora-all]
CVE-2017-6353 kernel: Possible double free in stcp_sendmsg() (incorrect fix for CVE-2017-5986) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects m
Bugzilla
CVE-2017-5986 kernel: Reachable BUG_ON from userspace in sctp_wait_for_sndbuf [fedora-all]
bugzilla·2017-02-13·CVSS 5.5
CVE-2017-5986 [MEDIUM] CVE-2017-5986 kernel: Reachable BUG_ON from userspace in sctp_wait_for_sndbuf [fedora-all]
CVE-2017-5986 kernel: Reachable BUG_ON from userspace in sctp_wait_for_sndbuf [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported
Bugzilla
CVE-2017-5986 kernel: Reachable BUG_ON from userspace in sctp_wait_for_sndbuf
bugzilla·2017-02-08·CVSS 5.5
CVE-2017-5986 [MEDIUM] CVE-2017-5986 kernel: Reachable BUG_ON from userspace in sctp_wait_for_sndbuf
CVE-2017-5986 kernel: Reachable BUG_ON from userspace in sctp_wait_for_sndbuf
It was reported that with Linux kernel, earlier than version v4.10-rc8, an application may trigger a BUG_ON in sctp_wait_for_sndbuf if the socket tx buffer is full, a thread is waiting on it to queue more data, and meanwhile another thread peels off the association being used by the first thread.
References:
https://lkml.org/lkml/2017/1/30/238
http://seclists.org/oss-sec/2017/q1/432
Upstream patch:
https://github.com/torvalds/linux/commit/2dcab598484185dea7ec22219c76dcdd59e3cb90
Discussion:
Upstream patch:
https://github.com/torvalds/linux/commit/2dcab598484185dea7ec22219c76dcdd59e3cb90
---
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1421741]
---
kernel-4.9.9-100.fc24 has b
arXiv
Characteristics, Root Causes, and Detection of Incomplete Security Bug Fixes in the Linux Kernel
arxiv_fulltext·2025-11-21
Characteristics, Root Causes, and Detection of Incomplete Security Bug Fixes in the Linux Kernel
Characteristics, Root Causes, and Detection of
Incomplete Security Bug Fixes in the Linux Kernel
Qiang Liu^1All work was done by Aug., 2022.,
Wenlong Zhang^1,
Muhui Jiang^2,1,
Lei Wu^1,
Yajin Zhou^1
^1Zhejiang University,
^2The Hong Kong Polytechnic University
## Abstract
Security bugs in the Linux kernel emerge endlessly and have attracted much
attention.
However, fixing security bugs in the Linux kernel could be incomplete due to
human mistakes.
Specifically, an incomplete fix fails to repair all the original security
defects in the software, fails to properly repair the original security defects,
or introduces new ones.
In this paper, we study the fixes of incomplete security bugs in the Linux
kernel for the first time, and reveal their characteristics, root causes as well
as de
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=2dcab598484185dea7ec22219c76dcdd59e3cb90http://www.debian.org/security/2017/dsa-3804http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.11http://www.openwall.com/lists/oss-security/2017/02/14/6http://www.securityfocus.com/bid/96222https://access.redhat.com/errata/RHSA-2017:1308https://bugzilla.redhat.com/show_bug.cgi?id=1420276https://github.com/torvalds/linux/commit/2dcab598484185dea7ec22219c76dcdd59e3cb90http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=2dcab598484185dea7ec22219c76dcdd59e3cb90http://www.debian.org/security/2017/dsa-3804http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.11http://www.openwall.com/lists/oss-security/2017/02/14/6http://www.securityfocus.com/bid/96222https://access.redhat.com/errata/RHSA-2017:1308https://bugzilla.redhat.com/show_bug.cgi?id=1420276https://github.com/torvalds/linux/commit/2dcab598484185dea7ec22219c76dcdd59e3cb90
2017-02-18
Published