CVE-2024-0639
MEDIUMDescription
A denial of service vulnerability due to a deadlock was found in sctp_auto_asconf_init in net/sctp/socket.c in the Linux kernel’s SCTP subsystem. This flaw allows guests with local user privileges to trigger a deadlock and potentially crash the system.
Is your site exposed to CVE-2024-0639?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| linux | linux_kernel |
| redhat | enterprise_linux |
| redhat | enterprise_linux |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2024-0639? +
How severe is CVE-2024-0639? +
What products are affected by CVE-2024-0639? +
How do I check if I'm vulnerable to CVE-2024-0639? +
Related Vulnerabilities
Webserver crash caused by scanning on TCP port 80 in Softing Industrial Automation GmbH gateways and switch.This issue affects smartLink …
Copyparty is a portable file server. Versions prior to 1.18.9, the filter parameter for the "Recent Uploads" page allows arbitrary …
When setting up interrupt remapping for legacy PCI(-X) devices, including PCI(-X) bridges, a lookup of the upstream bridge is required. …
Deadlock in PAM automatic check-in feature in Devolutions Server allows a password to remain valid beyond the end of its …
IBM Db2 for Linux 12.1.0, 12.1.1, and 12.1.2 could allow an unauthenticated user to cause a denial of service due …
boringproxy through 0.10.0 contains a resource exhaustion vulnerability that allows any authenticated user to permanently exhaust server file descriptors, goroutines, …