CVE-2017-6353 is a denial-of-service vulnerability affecting the Linux kernel (through version 4.10.1) in the net/sctp/socket.c component. It stems from an improper fix for a previous vulnerability, allowing local users to trigger an invalid unlock and double free condition through multithreaded applications during specific SCTP association peel-off operations. Rated as Medium severity (CVSS 5.5), this vulnerability requires local access and low attack complexity, with the primary impact being high availability loss. There is no confidentiality or integrity impact. Currently, there is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, indicating a lack of widespread attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.10CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.