PT-2025-37901 · Linux+4 · Linux Kernel+4

CVE-2023-53296

·

Published

2023-04-02

·

Updated

2026-06-30

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A flaw exists in the Linux kernel’s SCTP (Stream Control Transmission Protocol) implementation. Specifically, the issue arises from a corner case where the association (asoc) out stream count may change after wait for sndbuf. This can lead to a crash when a thread waiting for a send buffer is awakened and attempts to send a message on a non-existing stream. The vulnerability occurs when a client initiates a connection, and another thread concurrently sends messages with a stream number that becomes invalid after processing an INIT ACK.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Improper Resource Release

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
BDU:2026-02514
CESA-2023_7077
CVE-2023-53296
OESA-2025-2553
RHSA-2023:6583
RHSA-2023:7077
RHSA-2023_6583
RHSA-2023_7077
RHSA-2024:0575

Affected Products

Astra Linux
Centos
Linux Kernel
Red Hat
Red Os