CVE-2013-1828: Linux Kernel
Medium severity, CVSS 6.9. EPSS: 1% chance of exploitation in the next 30 days.
The sctp_getsockopt_assoc_stats function in net/sctp/socket.c in the Linux kernel before 3.8.4 does not validate a size value before proceeding to a copy_from_user operation, which allows local users to gain privileges via a crafted application that contains an SCTP_GET_ASSOC_STATS getsockopt system call.
Affected products
- Linux Linux Kernel: from 3.8, before 3.8.4 (fixed in 3.8.4)
Published 2013-03-22. Last modified 2026-06-16.