CVE-2024-50299

Source
https://cve.org/CVERecord?id=CVE-2024-50299
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-50299.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-50299
Downstream
Related
Published
2024-11-19T01:30:47.362Z
Modified
2026-03-11T07:51:30.713996Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
sctp: properly validate chunk size in sctp_sf_ootb()
Details

In the Linux kernel, the following vulnerability has been resolved:

sctp: properly validate chunk size in sctpsfootb()

A size validation fix similar to that in Commit 50619dbf8db7 ("sctp: add size validation when walking chunks") is also required in sctpsfootb() to address a crash reported by syzbot:

BUG: KMSAN: uninit-value in sctpsfootb+0x7f5/0xce0 net/sctp/smstatefuns.c:3712 sctpsfootb+0x7f5/0xce0 net/sctp/smstatefuns.c:3712 sctpdosm+0x181/0x93d0 net/sctp/smsideeffect.c:1166 sctpendpointbhrcv+0xc38/0xf90 net/sctp/endpointola.c:407 sctpinqpush+0x2ef/0x380 net/sctp/inqueue.c:88 sctprcv+0x3831/0x3b20 net/sctp/input.c:243 sctp4rcv+0x42/0x50 net/sctp/protocol.c:1159 ipprotocoldeliverrcu+0xb51/0x13d0 net/ipv4/ipinput.c:205 iplocaldeliverfinish+0x336/0x500 net/ipv4/ipinput.c:233

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/50xxx/CVE-2024-50299.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Fixed
67b9a278b80f71ec62091ded97c6bcbea33b5ec3
Fixed
9b5d42aeaf1a52f73b003a33da6deef7df34685f
Fixed
40b283ba76665437bc2ac72079c51b57b25bff9e
Fixed
a758aa6a773bb872196bcc3173171ef8996bddf0
Fixed
bf9bff13225baf5f658577f7d985fc4933d79527
Fixed
d3fb3cc83cf313e4f87063ce0f3fea76b071567b
Fixed
8820d2d6589f62ee5514793fff9b50c9f8101182
Fixed
0ead60804b64f5bd6999eec88e503c6a1a242d41

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-50299.json"