Описание
A race condition during TCP connection teardown can cause tcp_recv() to operate on a connection that has already been released. If tcp_conn_search() returns NULL while processing a SYN packet, a NULL pointer derived from stale context data is passed to tcp_backlog_is_full() and dereferenced without validation, leading to a crash.
EPSS
Процентиль: 12%
0.00039
Низкий
6.4 Medium
CVSS3
Дефекты
CWE-476
EPSS
Процентиль: 12%
0.00039
Низкий
6.4 Medium
CVSS3
Дефекты
CWE-476