cbcvebase.
CVE-2024-50299
published 2024-11-19

CVE-2024-50299: In the Linux kernel, the following vulnerability has been resolved: sctp: properly validate chunk size in sctp_sf_ootb() A size validation fix similar to that…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.26%
18.1th percentile
In the Linux kernel, the following vulnerability has been resolved: sctp: properly validate chunk size in sctp_sf_ootb() A size validation fix similar to that in Commit 50619dbf8db7 ("sctp: add size validation when walking chunks") is also required in sctp_sf_ootb() to address a crash reported by syzbot: BUG: KMSAN: uninit-value in sctp_sf_ootb+0x7f5/0xce0 net/sctp/sm_statefuns.c:3712 sctp_sf_ootb+0x7f5/0xce0 net/sctp/sm_statefuns.c:3712 sctp_do_sm+0x181/0x93d0 net/sctp/sm_sideeffect.c:1166 sctp_endpoint_bh_rcv+0xc38/0xf90 net/sctp/endpointola.c:407 sctp_inq_push+0x2ef/0x380 net/sctp/inqueue.c:88 sctp_rcv+0x3831/0x3b20 net/sctp/input.c:243 sctp4_rcv+0x42/0x50 net/sctp/protocol.c:1159 ip_protocol_deliver_rcu+0xb51/0x13d0 net/ipv4/ip_input.c:205 ip_local_deliver_finish+0x336/0x500 net/ipv4/ip_input.c:233

Affected

46 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.119-1 (bookworm)linux 6.1.119-1 (bookworm)
debianlinux-6.1< linux 6.1.119-1 (bookworm)linux 6.1.119-1 (bookworm)
linuxlinux
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 67b9a278b80f71ec62091ded97c6bcbea33b5ec367b9a278b80f71ec62091ded97c6bcbea33b5ec3
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 9b5d42aeaf1a52f73b003a33da6deef7df34685f9b5d42aeaf1a52f73b003a33da6deef7df34685f
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 40b283ba76665437bc2ac72079c51b57b25bff9e40b283ba76665437bc2ac72079c51b57b25bff9e
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < a758aa6a773bb872196bcc3173171ef8996bddf0a758aa6a773bb872196bcc3173171ef8996bddf0
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < bf9bff13225baf5f658577f7d985fc4933d79527bf9bff13225baf5f658577f7d985fc4933d79527
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < d3fb3cc83cf313e4f87063ce0f3fea76b071567bd3fb3cc83cf313e4f87063ce0f3fea76b071567b
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 8820d2d6589f62ee5514793fff9b50c9f81011828820d2d6589f62ee5514793fff9b50c9f8101182
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 0ead60804b64f5bd6999eec88e503c6a1a242d410ead60804b64f5bd6999eec88e503c6a1a242d41
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.119-16.1.119-1
linuxlinux_kernel>= 0 < 6.11.9-16.11.9-1
linuxlinux_kernel>= 0 < 6.11.9-16.11.9-1
linuxlinux_kernel>= 0 < 5.4.0-208.2285.4.0-208.228
linuxlinux_kernel>= 0 < 5.15.0-133.1445.15.0-133.144
linuxlinux_kernel>= 0 < 6.8.0-58.606.8.0-58.60
linuxlinux_kernel>= 0 < 6.11.0-18.186.11.0-18.18

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.