CyberRota Analysis
AI-GeneratedThe vulnerability affects the Linux kernel's SCTP (Stream Control Transmission Protocol) implementation, where the function responsible for verifying authentication can incorrectly validate packets when the authentication chunk is NULL. This flaw may allow unauthorized access or manipulation of SCTP connections, particularly in scenarios where authentication is expected but not enforced. System administrators and developers managing Linux-based systems that utilize SCTP should prioritize addressing this vulnerability to ensure secure communications.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: sctp: auth: verify auth requirement when auth_chunk is NULL sctp_auth_chunk_verify() returns true unconditionally when chunk->auth_chunk is NULL, silently skipping authentication. This is incorrect when: 1. skb_clone() failed in the BH receive path, leaving auth_chunk NULL. In sctp_endpoint_bh_rcv() asoc is NULL for new connections, so the early sctp_auth_recv_cid() check cannot catch this. 2. No AUTH chunk precedes COOKIE-ECHO, so skb_clone() is never called and auth_chunk remains NULL. Fix by checking sctp_auth_recv_cid() when auth_chunk is NULL: if authentication is required, return false to drop the chunk; otherwise continue normally.