Risk | Low |
Patch available | YES |
Number of vulnerabilities | 1 |
CVE-ID | CVE-2024-50299 |
CWE-ID | CWE-20 |
Exploitation vector | Local |
Public exploit | N/A |
Vulnerable software |
Linux kernel Operating systems & Components / Operating system |
Vendor | Linux Foundation |
Security Bulletin
This security bulletin contains one low risk vulnerability.
EUVDB-ID: #VU100631
Risk: Low
CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2024-50299
CWE-ID:
CWE-20 - Improper input validation
Exploit availability: No
DescriptionThe vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation within the sctp_sf_ootb() function in net/sctp/sm_statefuns.c. A local user can perform a denial of service (DoS) attack.
MitigationInstall update from vendor's website.
Vulnerable software versionsLinux kernel: 4.19 - 6.11.7
CPE2.3https://git.kernel.org/stable/c/67b9a278b80f71ec62091ded97c6bcbea33b5ec3
https://git.kernel.org/stable/c/9b5d42aeaf1a52f73b003a33da6deef7df34685f
https://git.kernel.org/stable/c/40b283ba76665437bc2ac72079c51b57b25bff9e
https://git.kernel.org/stable/c/a758aa6a773bb872196bcc3173171ef8996bddf0
https://git.kernel.org/stable/c/bf9bff13225baf5f658577f7d985fc4933d79527
https://git.kernel.org/stable/c/d3fb3cc83cf313e4f87063ce0f3fea76b071567b
https://git.kernel.org/stable/c/8820d2d6589f62ee5514793fff9b50c9f8101182
https://git.kernel.org/stable/c/0ead60804b64f5bd6999eec88e503c6a1a242d41
https://mirrors.edge.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.324
https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.230
https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.172
https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.286
https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.117
https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.11.8
https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12
https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.61
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.