CVE-2017-6353
published 2017-03-01CVE-2017-6353: net/sctp/socket.c in the Linux kernel through 4.10.1 does not properly restrict association peel-off operations during certain wait states, which allows local…
PriorityP418medium5.5CVSS 3.0
AVLACLPRLUINSUCNINAH
EPSS
0.37%
30.2th percentile
net/sctp/socket.c in the Linux kernel through 4.10.1 does not properly restrict association peel-off operations during certain wait states, which allows local users to cause a denial of service (invalid unlock and double free) via a multithreaded application. NOTE: this vulnerability exists because of an incorrect fix for CVE-2017-5986.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.9.13-1 (bookworm) | linux 4.9.13-1 (bookworm) |
| linux | linux_kernel | <= 4.10 | — |
| linux | linux_kernel | >= 0 < 4.9.13-1 | 4.9.13-1 |
| linux | linux_kernel | >= 0 < 4.9.13-1 | 4.9.13-1 |
| linux | linux_kernel | >= 0 < 4.9.13-1 | 4.9.13-1 |
| linux | linux_kernel | >= 0 < 4.9.13-1 | 4.9.13-1 |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8whq-7xh2-jxhw: net/sctp/socket
ghsa_unreviewed·2022-05-17·CVSS 5.5
CVE-2017-6353 [MEDIUM] CWE-415 GHSA-8whq-7xh2-jxhw: net/sctp/socket
net/sctp/socket.c in the Linux kernel through 4.10.1 does not properly restrict association peel-off operations during certain wait states, which allows local users to cause a denial of service (invalid unlock and double free) via a multithreaded application. NOTE: this vulnerability exists because of an incorrect fix for CVE-2017-5986.
OSV
CVE-2017-6353: net/sctp/socket
osv·2017-03-01·CVSS 5.5
CVE-2017-6353 [MEDIUM] CVE-2017-6353: net/sctp/socket
net/sctp/socket.c in the Linux kernel through 4.10.1 does not properly restrict association peel-off operations during certain wait states, which allows local users to cause a denial of service (invalid unlock and double free) via a multithreaded application. NOTE: this vulnerability exists because of an incorrect fix for CVE-2017-5986.
Red Hat
kernel: Possible double free in stcp_sendmsg() (incorrect fix for CVE-2017-5986)
vendor_redhat·2017-02-23·CVSS 5.5
CVE-2017-6353 [MEDIUM] CWE-416 kernel: Possible double free in stcp_sendmsg() (incorrect fix for CVE-2017-5986)
kernel: Possible double free in stcp_sendmsg() (incorrect fix for CVE-2017-5986)
net/sctp/socket.c in the Linux kernel through 4.10.1 does not properly restrict association peel-off operations during certain wait states, which allows local users to cause a denial of service (invalid unlock and double free) via a multithreaded application. NOTE: this vulnerability exists because of an incorrect fix for CVE-2017-5986.
It was found that the code in net/sctp/socket.c in the Linux kernel through 4.10.1 does not properly restrict association peel-off operations during certain wait states, which allows local users to cause a denial of service (invalid unlock and double free) via a multithreaded application. This vulnerability was introduced by CVE-2017-5986 fix (commit 2dcab5984841).
Statement
Debian
CVE-2017-6353: linux - net/sctp/socket.c in the Linux kernel through 4.10.1 does not properly restrict ...
vendor_debian·2017·CVSS 5.5
CVE-2017-6353 [MEDIUM] CVE-2017-6353: linux - net/sctp/socket.c in the Linux kernel through 4.10.1 does not properly restrict ...
net/sctp/socket.c in the Linux kernel through 4.10.1 does not properly restrict association peel-off operations during certain wait states, which allows local users to cause a denial of service (invalid unlock and double free) via a multithreaded application. NOTE: this vulnerability exists because of an incorrect fix for CVE-2017-5986.
Scope: local
bookworm: resolved (fixed in 4.9.13-1)
bullseye: resolved (fixed in 4.9.13-1)
forky: resolved (fixed in 4.9.13-1)
sid: resolved (fixed in 4.9.13-1)
trixie: resolved (fixed in 4.9.13-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-6353 kernel: Possible double free in stcp_sendmsg() (incorrect fix for CVE-2017-5986)
bugzilla·2017-03-03·CVSS 5.5
CVE-2017-6353 [MEDIUM] CVE-2017-6353 kernel: Possible double free in stcp_sendmsg() (incorrect fix for CVE-2017-5986)
CVE-2017-6353 kernel: Possible double free in stcp_sendmsg() (incorrect fix for CVE-2017-5986)
net/sctp/socket.c in the Linux kernel through 4.10.1 does not properly restrict association peel-off operations during certain wait states, which allows local users to cause a denial of service (invalid unlock and double free) via a multithreaded application.
This vulnerability was introduced by CVE-2017-5986 fix (commit 2dcab5984841).
Upstream patch:
https://github.com/torvalds/linux/commit/dfcb9f4f99f1e9a49e43398a7bfbf56927544af1
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1428910]
---
Statement:
This issue does not affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 5, 6, 7 and MRG-2, as the problem code is not presented in
Bugzilla
CVE-2017-6353 kernel: Possible double free in stcp_sendmsg() (incorrect fix for CVE-2017-5986) [fedora-all]
bugzilla·2017-03-03·CVSS 5.5
CVE-2017-6353 [MEDIUM] CVE-2017-6353 kernel: Possible double free in stcp_sendmsg() (incorrect fix for CVE-2017-5986) [fedora-all]
CVE-2017-6353 kernel: Possible double free in stcp_sendmsg() (incorrect fix for CVE-2017-5986) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects m
arXiv
Characteristics, Root Causes, and Detection of Incomplete Security Bug Fixes in the Linux Kernel
arxiv_fulltext·2025-11-21
Characteristics, Root Causes, and Detection of Incomplete Security Bug Fixes in the Linux Kernel
Characteristics, Root Causes, and Detection of
Incomplete Security Bug Fixes in the Linux Kernel
Qiang Liu^1All work was done by Aug., 2022.,
Wenlong Zhang^1,
Muhui Jiang^2,1,
Lei Wu^1,
Yajin Zhou^1
^1Zhejiang University,
^2The Hong Kong Polytechnic University
## Abstract
Security bugs in the Linux kernel emerge endlessly and have attracted much
attention.
However, fixing security bugs in the Linux kernel could be incomplete due to
human mistakes.
Specifically, an incomplete fix fails to repair all the original security
defects in the software, fails to properly repair the original security defects,
or introduces new ones.
In this paper, we study the fixes of incomplete security bugs in the Linux
kernel for the first time, and reveal their characteristics, root causes as well
as de
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=dfcb9f4f99f1e9a49e43398a7bfbf56927544af1http://www.debian.org/security/2017/dsa-3804http://www.openwall.com/lists/oss-security/2017/02/27/2http://www.securityfocus.com/bid/96473https://github.com/torvalds/linux/commit/dfcb9f4f99f1e9a49e43398a7bfbf56927544af1http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=dfcb9f4f99f1e9a49e43398a7bfbf56927544af1http://www.debian.org/security/2017/dsa-3804http://www.openwall.com/lists/oss-security/2017/02/27/2http://www.securityfocus.com/bid/96473https://github.com/torvalds/linux/commit/dfcb9f4f99f1e9a49e43398a7bfbf56927544af1
2017-03-01
Published