PT-2025-37901 · Linux+3 · Linux Kernel+3

Published

2023-04-02

·

Updated

2025-10-31

·

CVE-2023-53296

CVSS v2.0

6.0

Medium

VectorAV:L/AC:H/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A flaw exists in the Linux kernel’s SCTP (Stream Control Transmission Protocol) implementation. Specifically, the issue arises from a corner case where the association (asoc) out stream count may change after wait for sndbuf. This can lead to a crash when a thread waiting for a send buffer is awakened and attempts to send a message on a non-existing stream. The vulnerability occurs when a client initiates a connection, and another thread concurrently sends messages with a stream number that becomes invalid after processing an INIT ACK.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Resource Release

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
BDU:2026-02514
CESA-2023_7077
CVE-2023-53296
OESA-2025-2553
RHSA-2023:6583
RHSA-2023:7077
RHSA-2023_6583
RHSA-2023_7077
RHSA-2024:0575

Affected Products

Astra Linux
Centos
Linux Kernel
Red Hat