CVE-2017-5986: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 1.2% chance of exploitation in the next 30 days.

Race condition in the sctp_wait_for_sndbuf function in net/sctp/socket.c in the Linux kernel before 4.9.11 allows local users to cause a denial of service (assertion failure and panic) via a multithreaded application that peels off an association in a certain buffer-full state.

Affected products

  • Linux Linux Kernel: up to and including 4.9.11

Published 2017-02-18. Last modified 2026-06-17.