VYPR
High severity7.8NVD Advisory· Published Dec 31, 2004· Updated Jun 16, 2026

CVE-2004-2013

CVE-2004-2013

Description

Integer overflow in the SCTP_SOCKOPT_DEBUG_NAME SCTP socket option in socket.c in the Linux kernel 2.4.25 and earlier allows local users to execute arbitrary code via an optlen value of -1, which causes kmalloc to allocate 0 bytes of memory.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Linux/Kernel2 versions
    cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*range: <=2.4.25
    • (no CPE)range: <=2.4.25

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.