In the Linux kernel, the following vulnerability has been resolved: net/sctp: Prevent autoclose integer overflow in sctp_association_init() While by default max_autoclose equals to INT_MAX / HZ, one may set net.sctp.max_autoclose to UINT_MAX. There is code in sctp_association_init() that can consequently trigger overflow.
Product | Vendor | Version |
---|---|---|
Linux | Linux | < 20.2R3-S5 |
Linux | Linux | NX701-[][][][] Ver.1.35.00 and earlier |