Integer overflow in the SCTP_SOCKOPT_DEBUG_NAME SCTP socket option in socket.c in the Linux kernel 2.4.25 and earlier allows local users to execute arbitrary code via an optlen value of -1, which causes kmalloc to allocate 0 bytes of memory.
Score: 1.8
Priority: P4 - Informational (Low)
Score: 0.00086
Percentile:
0.25945
CVSS v3.1 Score: 7.8
Severity: HIGH