CyberRota Analysis
AI-GeneratedThe vulnerability affects the Linux kernel's SCTP (Stream Control Transmission Protocol) implementation, specifically in the handling of the transport_count, which can overflow when adding a large number of unique peers. This overflow can lead to a denial-of-service condition by allowing excessive memory allocation, potentially resulting in a crash or instability of the system. Organizations using Linux systems that rely on SCTP should prioritize this issue to mitigate risks associated with service disruptions and ensure system reliability.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: sctp: prevent peer transport count overflow sctp_assoc_add_peer() increments the association's 16-bit transport_count for every new unique peer. Adding the 65,536th transport wraps the count to zero. SCTP sock_diag uses transport_count to reserve the INET_DIAG_PEERS payload, then copies one sockaddr_storage for every entry in transport_addr_list. After the wrap, a diagnostic dump reserves an empty payload and writes 8 MiB of peer addresses past the skb tail. Reject a new unique peer when transport_count has reached U16_MAX. Perform the check after the existing-peer lookup so a duplicate address continues to return its existing transport at the limit.