CVE-2019-8956
HIGHLinux Kernel 4.17-4.19.20 - Use-After-Free in SCTP Sendmsg Function
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-8956. PoCs published by butterflyhack.
AI-analyzed exploit summary This PoC exploits CVE-2019-8956, a vulnerability in the SCTP protocol implementation, by sending malformed SCTP messages to trigger a denial-of-service condition. The code demonstrates the exploit by creating multiple threads to send and receive SCTP messages with specific flags.
Description
In the Linux Kernel before versions 4.20.8 and 4.19.21 a use-after-free error in the "sctp_sendmsg()" function (net/sctp/socket.c) when handling SCTP_SENDALL flag can be exploited to corrupt memory.
Exploits (1)
This PoC exploits CVE-2019-8956, a vulnerability in the SCTP protocol implementation, by sending malformed SCTP messages to trigger a denial-of-service condition. The code demonstrates the exploit by creating multiple threads to send and receive SCTP messages with specific flags.
References (7)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H