A denial of service vulnerability due to a deadlock was found in sctpautoasconf_init in net/sctp/socket.c in the Linux kernel’s SCTP subsystem. This flaw allows guests with local user privileges to trigger a deadlock and potentially crash the system.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-0639.json"
[
{
"target": {
"file": "net/sctp/socket.c"
},
"digest": {
"line_hashes": [
"51771505424137924125752888224014173160",
"294274385537353799167346758433064554399",
"273097177576053870351996542885208049612",
"65177069722789618045617970494145291819",
"192397901080456339629467941674451035737",
"219684794986888354321427203552511667064"
],
"threshold": 0.9
},
"signature_type": "Line",
"id": "CVE-2024-0639-8ab2e7f6",
"source": "https://github.com/torvalds/linux/commit/6feb37b3b06e9049e20dcf7e23998f92c9c5be9a",
"deprecated": false,
"signature_version": "v1"
}
]