CVE-2024-57938 - CVE House
Back to Database
Status published Unknown CVE-2024-57938

net/sctp: Prevent autoclose integer overflow in sctp_association_init()

Vulnerability Description

In the Linux kernel, the following vulnerability has been resolved: net/sctp: Prevent autoclose integer overflow in sctp_association_init() While by default max_autoclose equals to INT_MAX / HZ, one may set net.sctp.max_autoclose to UINT_MAX. There is code in sctp_association_init() that can consequently trigger overflow.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-57938

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Linux
Vulnerable Versions:
9f70f46bd4c7267d48ef461a1d613ec9ec0d520c, 3.13, 0, 5.4.289, 5.10.233, 5.15.176, 6.1.124, 6.6.70, 6.12.9, 6.13

Timeline

Official Publish: January 21st, 2025
Last Modified: May 11th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.