The sctpsfootb function in net/sctp/sm_statefuns.c in the Linux kernel before 4.8.8 lacks chunk-length checking for the first chunk, which allows remote attackers to cause a denial of service (out-of-bounds slab access) or possibly have unspecified other impact via crafted SCTP data.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-9555.json"
[
{
"target": {
"file": "net/sctp/sm_statefuns.c"
},
"digest": {
"line_hashes": [
"314104629900571035076435554712152869878",
"252720086853680238173833386233866742984",
"8909361858875140532837714650762455724",
"331605234808139114525187106338339997615",
"249558955640156501710498681902715292327",
"247511596609925246024144912941106339594",
"206831940057939247297999507784512171277",
"176161721598571535820627584448394644355",
"56415626073246639707627941713453749015",
"221573851488874330210986880395469972230"
],
"threshold": 0.9
},
"signature_type": "Line",
"id": "CVE-2016-9555-2beb59e6",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@bf911e985d6bbaa328c20c3e05f4eb03de11fdd6",
"deprecated": false,
"signature_version": "v1"
},
{
"target": {
"file": "net/sctp/sm_statefuns.c",
"function": "sctp_sf_ootb"
},
"digest": {
"length": 1286.0,
"function_hash": "194180893947637348720783747601557700005"
},
"signature_type": "Function",
"id": "CVE-2016-9555-a85570e9",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@bf911e985d6bbaa328c20c3e05f4eb03de11fdd6",
"deprecated": false,
"signature_version": "v1"
}
]