Kernel: potential deadlock on &net->sctp.addr_wq_lock leading to dos
Summary
A denial of service vulnerability due to a deadlock was found in sctp_auto_asconf_init in net/sctp/socket.c in the Linux kernel’s SCTP subsystem. This flaw allows guests with local user privileges to trigger a deadlock and potentially crash the system. Affected products named by the advisory: Red Hat Enterprise Linux 9.
What this means
In plain English
A denial of service vulnerability due to a deadlock was found in sctp_auto_asconf_init in net/sctp/socket.c in the Linux kernel’s SCTP subsystem. This flaw allows guests with local user privileges to trigger a deadlock and potentially crash the system. Affected products named by the advisory: Red Hat Enterprise Linux 9. The official description requires local access to the affected system. Successful exploitation can interrupt the affected service or exhaust resources, reducing availability until the component recovers.
Recommended action
Primary action: update to a vendor-listed fixed release: 6.5-rc1.
Rewritten locally from the scraped official advisory data above; no generative API is used. The vendor advisory is authoritative.
- before 6.5-rc1
Official advisory · high-confidence parse· fetched 4 hours ago·verify at source
- 6.5-rc1
Official advisory · high-confidence parse· fetched 4 hours ago·verify at source
Mitigation
Upgrade to a fixed release: 6.5-rc1. That is the remediation for this advisory.
The vendor advisory may list additional interim mitigations or workarounds not captured here — review it before change work.
Official advisory · high-confidence parse· fetched 4 hours ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.