CVE-2017-6353: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.4% chance of exploitation in the next 30 days.

net/sctp/socket.c in the Linux kernel through 4.10.1 does not properly restrict association peel-off operations during certain wait states, which allows local users to cause a denial of service (invalid unlock and double free) via a multithreaded application. NOTE: this vulnerability exists because of an incorrect fix for CVE-2017-5986.

Affected products

  • Linux Linux Kernel: up to and including 4.10

Published 2017-03-01. Last modified 2026-06-17.