CVE-2019-20503 is an out-of-bounds read vulnerability in usrsctp versions prior to 2019-12-20, specifically within the sctp_load_addresses_from_init function. This flaw affects various distributions including Canonical and Debian Linux, as well as the usrsctp project itself. With a CVSS score of 6.5 (Medium), it can be exploited remotely with low attack complexity, potentially leading to high availability impact, though it does not affect confidentiality or integrity. There is no evidence of active exploitation, public exploit code, or inclusion in CISA’s KEV catalog, despite moderate community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.9.4.0CPE matchmatch criteria | cpe:2.3:a:usrsctp_project:usrsctp:*:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* | ||
16.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.