CVE-2013-1828
Linux Kernel < 3.8.4 - Improper Input Validation
Title source: ruleDescription
The sctp_getsockopt_assoc_stats function in net/sctp/socket.c in the Linux kernel before 3.8.4 does not validate a size value before proceeding to a copy_from_user operation, which allows local users to gain privileges via a crafted application that contains an SCTP_GET_ASSOC_STATS getsockopt system call.
Exploits (1)
References (8)
Scores
EPSS
0.0024
EPSS Percentile
47.9%
Details
CWE
CWE-20
Status
published
Products (1)
linux/linux_kernel
3.8 - 3.8.4
Published
Mar 22, 2013
Tracked Since
Feb 18, 2026