High severity7.8NVD Advisory· Published Dec 31, 2004· Updated Jun 16, 2026
CVE-2004-2013
CVE-2004-2013
Description
Integer overflow in the SCTP_SOCKOPT_DEBUG_NAME SCTP socket option in socket.c in the Linux kernel 2.4.25 and earlier allows local users to execute arbitrary code via an optlen value of -1, which causes kmalloc to allocate 0 bytes of memory.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
5- marc.infonvdMailing ListPatch
- archives.neohapsis.com/archives/bugtraq/2004-05/0091.htmlnvdBroken LinkExploitPatch
- www.securityfocus.com/bid/10326nvdBroken LinkThird Party AdvisoryVDB Entry
- exchange.xforce.ibmcloud.com/vulnerabilities/16117nvdThird Party AdvisoryVDB Entry
- lists.netsys.com/pipermail/full-disclosure/2004-May/021223.htmlnvdBroken Link
News mentions
0No linked articles in our index yet.