CVE-2017-5986 describes a race condition in the Linux kernel's SCTP implementation (sctp_wait_for_sndbuf function) affecting versions prior to 4.9.11. This vulnerability allows a local, unprivileged attacker to trigger a denial of service (assertion failure and kernel panic) by manipulating a multithreaded application that peels off an association in a specific buffer-full state. Rated Medium severity (CVSS 5.5), it requires local access and user interaction to exploit, leading to high availability impact. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.9.11CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.