CVE-2022-0322: Fedoraproject Fedora

Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.

A flaw was found in the sctp_make_strreset_req function in net/sctp/sm_make_chunk.c in the SCTP network protocol in the Linux kernel with a local user privilege access. In this flaw, an attempt to use more buffer than is allocated triggers a BUG_ON issue, leading to a denial of service (DOS).

Affected products

  • Fedoraproject Fedora: version 35 only
  • Linux Linux Kernel: before 5.15 (fixed in 5.15); version 5.15 only
  • Oracle Communications Cloud Native Core Binding Support Function: version 22.1.3 only
  • Oracle Communications Cloud Native Core Network Exposure Function: version 22.1.1 only
  • Oracle Communications Cloud Native Core Policy: version 22.2.0 only

Published 2022-03-25. Last modified 2026-06-17.