Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Tue, 22 Nov 2016 10:52:44 +0100
From: Andrey Konovalov <>
Cc:, Dmitry Vyukov <>, 
	Kostya Serebryany <>
Subject: CVE Request: Linux: net/sctp: slab-out-of-bounds in sctp_sf_ootb


There's a bug in the Linux kernel sctp implementation which allows a
remote attacker to trigger a slab-out-of-bounds access with an offset
up to 64K bytes.

The bug was fixed upstream:

More details are here:!topic/syzkaller/pAUcHsUJbjk

Could you assign a CVE for this?


Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.