CVE-2025-38718

sctp: linearize cloned gso packets in sctp_rcv

References

Notes

 carnil> Introduced in 90017accff61 ("sctp: Add GSO support"). Vulnerable versions: 4.8.

Bugs

Status

Branch Status
upstream released (6.17-rc2) [fd60d8a086191fe33c2d719732d2482052fa6805]
6.18-upstream-stable N/A "Fixed before branching point"
6.17-upstream-stable N/A "Fixed before branching point"
6.16-upstream-stable released (6.16.2) [1bd5214ea681584c5886fea3ba03e49f93a43c0e]
6.15-upstream-stable released (6.15.11) [fc66772607101bd2030a4332b3bd0ea3b3605250]
6.12-upstream-stable released (6.12.43) [7d757f17bc2ef2727994ffa6d5d6e4bc4789a770]
6.6-upstream-stable released (6.6.103) [ea094f38d387d1b0ded5dee4a3e5720aa4ce0139]
6.1-upstream-stable needed
5.10-upstream-stable released (5.10.241) [03d0cc6889e02420125510b5444b570f4bbf53d5]
sid released (6.16.3-1)
6.12-trixie-security released (6.12.43-1)
6.1-bookworm-security needed
5.10-bullseye-security released (5.10.244-1)