CVE-2019-8956
HIGH 7.8EPSS 1.1%
In the Linux Kernel before versions 4.20.8 and 4.19.21 a use-after-free error in the "sctp_sendmsg()" function (net/sctp/socket.c) when handling SCTP_SENDALL flag can be exploited to corrupt memory.
- CVSS v3.1
- 7.8 HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C - EPSS
- 1.13% chance of exploitation in the next 30 days, 64th percentile
- Published
- 2019-04-01
- Updated
- 2024-08-04
Proof-of-concept exploits (3)
- Michael23Yu/POC0★ · 2019-05-28
- butterflyhack/CVE-2019-89568★ · 2019-05-28
- exube/sctp_uaf0★ · 2019-12-15