Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2019-20503

24
FAUCET Score

CVE-2019-20503 is an out-of-bounds read vulnerability in usrsctp versions prior to 2019-12-20, specifically within the sctp_load_addresses_from_init function. This flaw affects various distributions including Canonical and Debian Linux, as well as the usrsctp project itself. With a CVSS score of 6.5 (Medium), it can be exploited remotely with low attack complexity, potentially leading to high availability impact, though it does not affect confidentiality or integrity. There is no evidence of active exploitation, public exploit code, or inclusion in CISA’s KEV catalog, despite moderate community discussion and media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
< 0.9.4.0CPE matchmatch criteria
cpe:2.3:a:usrsctp_project:usrsctp:*:*:*:*:*:*:*:*
8.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
9.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
10.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
16.04CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.5MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
3.16%
Probability of exploitation in next 30 days
EPSS Percentile
86.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0316 is in the 94th percentile among its peer group of 26,219 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (19)

github_advisorypatch availablevia nvd_reference
View patch
microsoftpatch availablevia msrc
Product: 17049-16823Fixed in: 0.9.5.0-1
microsoftpatch availablevia msrc
Product: 17050-16817Fixed in: 0.9.5.0-1
microsoftpatch availablevia msrc
Product: 17050-17084Fixed in: 0.9.5.0-1
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 ARMFixed in: 0.9.5.0-1
microsoftpatch availablevia msrc
Product: cbl2 usrsctp 0.9.5.0-1 on CBL Mariner 2.0Fixed in: 0.9.5.0-1
microsoftpatch availablevia msrc
Product: azl3 usrsctp 0.9.5.0-1 on Azure Linux 3.0Fixed in: 0.9.5.0-1
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 x64Fixed in: 0.9.5.0-1
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 ARMFixed in: 0.9.5.0-1
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 x64Fixed in: 0.9.5.0-1
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: thunderbird-0:68.6.0-1.el8_1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.0 Update Services for SAP SolutionsFixed in: firefox-0:68.6.0-1.el8_0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.0 Update Services for SAP SolutionsFixed in: thunderbird-0:68.6.0-1.el8_0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: firefox-0:68.6.0-1.el6_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: thunderbird-0:68.6.0-1.el6_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6 SupplementaryFixed in: chromium-browser-0:80.0.3987.149-1.el6_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: firefox-0:68.6.0-1.el7_7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: thunderbird-0:68.6.0-1.el7_7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: firefox-0:68.6.0-1.el8_1
View patch

Vendor Advisories (3)

microsoft2024-Jun/CVE-2019-20503

CVE-2019-20503

Jun 11, 2024
microsoft2020-Mar/CVE-2019-20503Moderate

usrsctp before 2019-12-20 has out-of-bounds reads in sctp_load_addresses_from_init.

Mar 10, 2020
redhatCVE-2019-20503Moderate

usrsctp: Out of bounds reads in sctp_load_addresses_from_init()

Mar 10, 2020

References

lists.opensuse.org / opensuse-security-announce/2020-03/msg00022.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2020-03/msg00028.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2020-03/msg00030.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2020-03/msg00037.html
Mailing ListThird Party Advisory
access.redhat.com / errata/RHSA-2020:0815
Third Party Advisory
access.redhat.com / errata/RHSA-2020:0816
Third Party Advisory
access.redhat.com / errata/RHSA-2020:0819
Third Party Advisory
access.redhat.com / errata/RHSA-2020:0820
Third Party Advisory
bugs.chromium.org / p/project-zero/issues/detail
ExploitPatchVendor Advisory
chromereleases.googleblog.com / 2020/03/stable-channel-update-for-desktop_18.html
Third Party Advisory
crbug.com / 1059349
Third Party Advisory
seclists.org / fulldisclosure/2020/May/49
Mailing ListThird Party Advisory
seclists.org / fulldisclosure/2020/May/52
Mailing ListThird Party Advisory
seclists.org / fulldisclosure/2020/May/55
Mailing ListThird Party Advisory
seclists.org / fulldisclosure/2020/May/59
Mailing ListThird Party Advisory
github.com / sctplab/usrsctp/commit/790a7a2555aefb392a5a69923f1e9d17b4968467
PatchThird Party Advisory
lists.debian.org / debian-lts-announce/2020/03/msg00013.html
Mailing ListThird Party Advisory
lists.debian.org / debian-lts-announce/2020/03/msg00023.html
Mailing ListThird Party Advisory
lists.debian.org / debian-lts-announce/2023/07/msg00003.html
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/2DDNOAGIX5D77TTHT6YPMVJ5WTXTCQEI
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/6IOHSO6BUKC6I66J5PZOMAGFVJ66ZS57
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/JWANFIR3PYAL5RJQ4AO3ZS2DYMSF2ZGZ
Mailing ListThird Party Advisory
security.gentoo.org / glsa/202003-02
Third Party Advisory
security.gentoo.org / glsa/202003-10
Third Party Advisory
support.apple.com / HT211168
Third Party Advisory
support.apple.com / HT211171
Third Party Advisory
support.apple.com / HT211175
Third Party Advisory
support.apple.com / HT211177
Third Party Advisory
support.apple.com / kb/HT211168
Third Party Advisory
support.apple.com / kb/HT211171
Third Party Advisory
support.apple.com / kb/HT211175
Third Party Advisory
support.apple.com / kb/HT211177
Third Party Advisory
usn.ubuntu.com / 4299-1
Third Party Advisory
usn.ubuntu.com / 4328-1
Third Party Advisory
usn.ubuntu.com / 4335-1
Third Party Advisory
debian.org / security/2020/dsa-4639
Third Party Advisory
debian.org / security/2020/dsa-4642
Third Party Advisory
debian.org / security/2020/dsa-4645
Third Party Advisory