cbcvebase.
CVE-2024-57938
published 2025-01-21

CVE-2024-57938: In the Linux kernel, the following vulnerability has been resolved: net/sctp: Prevent autoclose integer overflow in sctp_association_init() While by default…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.21%
10.9th percentile
In the Linux kernel, the following vulnerability has been resolved: net/sctp: Prevent autoclose integer overflow in sctp_association_init() While by default max_autoclose equals to INT_MAX / HZ, one may set net.sctp.max_autoclose to UINT_MAX. There is code in sctp_association_init() that can consequently trigger overflow.

Affected

24 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.124-1 (bookworm)linux 6.1.124-1 (bookworm)
debianlinux-6.1< linux 6.1.124-1 (bookworm)linux 6.1.124-1 (bookworm)
linuxlinux
linuxlinux>= 9f70f46bd4c7267d48ef461a1d613ec9ec0d520c < 94b7ed0a4896420988e1776942f0a3f67167873e94b7ed0a4896420988e1776942f0a3f67167873e
linuxlinux>= 9f70f46bd4c7267d48ef461a1d613ec9ec0d520c < 081bdb3a31674339313c6d702af922bc29de2c53081bdb3a31674339313c6d702af922bc29de2c53
linuxlinux>= 9f70f46bd4c7267d48ef461a1d613ec9ec0d520c < f9c3adb083d3278f065a83c3f667f1246c74c31ff9c3adb083d3278f065a83c3f667f1246c74c31f
linuxlinux>= 9f70f46bd4c7267d48ef461a1d613ec9ec0d520c < 7af63ef5fe4d480064eb22583b24ffc8b408183a7af63ef5fe4d480064eb22583b24ffc8b408183a
linuxlinux>= 9f70f46bd4c7267d48ef461a1d613ec9ec0d520c < 271f031f4c31c07e2a85a1ba2b4c8e734909a477271f031f4c31c07e2a85a1ba2b4c8e734909a477
linuxlinux>= 9f70f46bd4c7267d48ef461a1d613ec9ec0d520c < 2297890b778b0e7c8200d6818154f7e461d78e942297890b778b0e7c8200d6818154f7e461d78e94
linuxlinux>= 9f70f46bd4c7267d48ef461a1d613ec9ec0d520c < 4e86729d1ff329815a6e8a920cb554a1d4cb5b8d4e86729d1ff329815a6e8a920cb554a1d4cb5b8d
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.124-16.1.124-1
linuxlinux_kernel>= 0 < 6.12.9-16.12.9-1
linuxlinux_kernel>= 0 < 6.12.9-16.12.9-1
linuxlinux_kernel>= 0 < 5.4.0-211.2315.4.0-211.231
linuxlinux_kernel>= 0 < 5.15.0-135.1465.15.0-135.146
linuxlinux_kernel>= 0 < 6.8.0-60.636.8.0-60.63
linuxlinux_kernel>= 3.13 < 5.4.2895.4.289
linuxlinux_kernel>= 5.11 < 5.15.1765.15.176
linuxlinux_kernel>= 5.16 < 6.1.1246.1.124
linuxlinux_kernel>= 5.5 < 5.10.2335.10.233
linuxlinux_kernel>= 6.2 < 6.6.706.6.70
linuxlinux_kernel>= 6.7 < 6.12.96.12.9

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.