CVE-2016-9555: Linux Kernel

Critical severity, CVSS 9.8. EPSS: 10% chance of exploitation in the next 30 days.

The sctp_sf_ootb function in net/sctp/sm_statefuns.c in the Linux kernel before 4.8.8 lacks chunk-length checking for the first chunk, which allows remote attackers to cause a denial of service (out-of-bounds slab access) or possibly have unspecified other impact via crafted SCTP data.

Affected products

  • Linux Linux Kernel: from 3.2, before 3.2.85 (fixed in 3.2.85); from 3.3, before 3.10.105 (fixed in 3.10.105); from 3.11, before 3.12.68 (fixed in 3.12.68); from 3.13, before 3.16.40 (fixed in 3.16.40); from 3.17, before 3.18.49 (fixed in 3.18.49); from 3.19, before 4.4.32 (fixed in 4.4.32); …

Published 2016-11-28. Last modified 2026-06-17.