Executive Summary



This Alert is flagged as TOP 25 Common Weakness Enumeration from CWE/SANS. For more information, you can read this.
Informations
Name CVE-2024-57938 First vendor Publication 2025-01-21
Vendor Cve Last vendor Modification 2025-01-22

Security-Database Scoring CVSS v3

Cvss vector : CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Overall CVSS Score 5.5
Base Score 5.5 Environmental Score 5.5
impact SubScore 3.6 Temporal Score 5.5
Exploitabality Sub Score 1.8
 
Attack Vector Local Attack Complexity Low
Privileges Required Low User Interaction None
Scope Unchanged Confidentiality Impact None
Integrity Impact None Availability Impact High
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector :
Cvss Base Score N/A Attack Range N/A
Cvss Impact Score N/A Attack Complexity N/A
Cvss Expoit Score N/A Authentication N/A
Calculate full CVSS 2.0 Vectors scores

Detail

In the Linux kernel, the following vulnerability has been resolved:

net/sctp: Prevent autoclose integer overflow in sctp_association_init()

While by default max_autoclose equals to INT_MAX / HZ, one may set net.sctp.max_autoclose to UINT_MAX. There is code in sctp_association_init() that can consequently trigger overflow.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-57938

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-190 Integer Overflow or Wraparound (CWE/SANS Top 25)

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 8
Os 3687

Sources (Detail)

https://git.kernel.org/stable/c/081bdb3a31674339313c6d702af922bc29de2c53
https://git.kernel.org/stable/c/2297890b778b0e7c8200d6818154f7e461d78e94
https://git.kernel.org/stable/c/271f031f4c31c07e2a85a1ba2b4c8e734909a477
https://git.kernel.org/stable/c/4e86729d1ff329815a6e8a920cb554a1d4cb5b8d
https://git.kernel.org/stable/c/7af63ef5fe4d480064eb22583b24ffc8b408183a
https://git.kernel.org/stable/c/94b7ed0a4896420988e1776942f0a3f67167873e
https://git.kernel.org/stable/c/f9c3adb083d3278f065a83c3f667f1246c74c31f
Source Url

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
Date Informations
2025-03-19 03:17:27
  • Multiple Updates
2025-03-18 03:30:26
  • Multiple Updates
2025-03-14 03:17:32
  • Multiple Updates
2025-03-06 14:14:06
  • Multiple Updates
2025-02-22 03:27:36
  • Multiple Updates
2025-01-23 05:20:33
  • Multiple Updates
2025-01-21 17:20:29
  • First insertion