CVE-2024-49944

Updated: 2025-02-27 13:59:54.747793

Description:

In the Linux kernel, the following vulnerability has been resolved: sctp: set sk_state back to CLOSED if autobind fails in sctp_listen_start In sctp_listen_start() invoked by sctp_inet_listen(), it should set the sk_state back to CLOSED if sctp_autobind() fails due to whatever reason. Otherwise, next time when calling sctp_inet_listen(), if sctp_sk(sk)->reuse is already set via setsockopt(SCTP_REUSE_PORT), sctp_sk(sk)->bind_hash will be dereferenced as sk_state is LISTENING, which causes a crash as bind_hash is NULL. KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007] RIP: 0010:sctp_inet_listen+0x7f0/0xa20 net/sctp/socket.c:8617 Call Trace: <TASK> __sys_listen_socket net/socket.c:1883 [inline] __sys_listen+0x1b7/0x230 net/socket.c:1894 __do_sys_listen net/socket.c:1902 [inline]


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0
CVSS Version 3.x MEDIUM 5.5

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU kernel 5.14.0 5.5 MEDIUM Ignored 2025-03-02 21:45:46
CentOS 6 ELS kernel 2.6.32 5.5 MEDIUM Ignored 2025-03-02 21:45:46
CentOS 7 ELS kernel 3.10.0 5.5 MEDIUM Ignored 2025-03-02 21:45:45
CentOS 8.4 ELS kernel 4.18.0 5.5 MEDIUM Ignored 2025-03-02 21:45:45
CentOS 8.5 ELS kernel 4.18.0 5.5 MEDIUM Ignored 2025-03-02 21:45:46
CentOS Stream 8 ELS kernel 4.18.0 5.5 MEDIUM Ignored 2025-03-02 21:45:45
CloudLinux 6 ELS kernel 2.6.32 5.5 MEDIUM Ignored 2025-03-02 21:45:46
CloudLinux 7 ELS kernel 3.10.0 5.5 MEDIUM Ignored 2025-03-02 21:45:45
Oracle Linux 6 ELS kernel 2.6.32 5.5 MEDIUM Ignored 2025-03-02 21:45:45
Oracle Linux 7 ELS kernel 3.10.0 5.5 MEDIUM Ignored 2025-03-02 21:45:45
Total: 13