Lksctp is a Linux kernel implementation of the Stream Control Transmission Protocol (SCTP), a specialized transport-layer protocol for reliable, message-oriented communication in networking and telecommunications systems. Observed vulnerabilities in this implementation cluster around improper locking mechanisms, a recurring concern in kernel-level protocol handlers where concurrent access and state synchronization are critical to correctness.
The number and severity of CVEs published that impact products developed by Lksctp over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-2271HIGH The ECNE chunk handling in Linux SCTP (lksctp) before 2.6.17 allows remote attackers to cause a denial of service (kernel panic) via an unexpected chunk when the session is in CLOS | May 9, 2006 | 7.8 | 21 | NO | NO |
CVE-2006-2272HIGH Linux SCTP (lksctp) before 2.6.17 allows remote attackers to cause a denial of service (kernel panic) via incoming IP fragmented (1) COOKIE_ECHO and (2) HEARTBEAT SCTP control chun | May 9, 2006 | 7.8 | 21 | NO | NO |
CVE-2006-2275HIGH Linux SCTP (lksctp) before 2.6.17 allows remote attackers to cause a denial of service (deadlock) via a large number of small messages to a receiver application that cannot process | May 9, 2006 | 7.5 | 20 | NO | NO |
CVE-2006-2274MEDIUM Linux SCTP (lksctp) before 2.6.17 allows remote attackers to cause a denial of service (infinite recursion and crash) via a packet that contains two or more DATA fragments, which c | May 9, 2006 | 5.0 | 16 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lksctp.
Media articles that mention a CVE ID that affects a product developed by Lksctp — matched by CVE ID, not by vendor name.