9.8
CVE-2026-68161
- EPSS 0.63%
- Veröffentlicht 10.08.2026 11:59:28
- Zuletzt bearbeitet 03.10.2026 11:17:35
- Erkennungen
sctp: close UDP tunnel sockets during netns teardown
In the Linux kernel, the following vulnerability has been resolved: sctp: close UDP tunnel sockets during netns teardown proc_sctp_do_udp_port() starts per-net SCTP UDP tunneling sockets when net.sctp.udp_port is set, and stops/restarts them when the sysctl value changes. The netns exit path does not stop these sockets, so a namespace can be torn down while its SCTP UDP tunnel sockets are still installed. Close the UDP tunnel sockets from sctp_ctrlsock_exit() after unregistering the per-net sysctl table. This prevents new sysctl writes from racing in while the sockets are being released, and closes the sockets before the control socket is destroyed.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
046c052b475e7119b6a30e3483e2888fc606a2f8
Version <
c29affd44e6769e3073235d4b471d9b501fa8166
Status
affected
Version
046c052b475e7119b6a30e3483e2888fc606a2f8
Version <
c6eb2d615210b80339548ab07c0230edaab9a6c7
Status
affected
Version
046c052b475e7119b6a30e3483e2888fc606a2f8
Version <
8ff78591d309c50a4fdab683b68dd8d512a270dd
Status
affected
Version
046c052b475e7119b6a30e3483e2888fc606a2f8
Version <
3bf0e349cbb4f975f35eb22753acc346b89c66a0
Status
affected
Version
046c052b475e7119b6a30e3483e2888fc606a2f8
Version <
37ff9794be48d0caa37687e04d09675f9c849121
Status
affected
Version
046c052b475e7119b6a30e3483e2888fc606a2f8
Version <
ffb2bd7ade36ec4da32c46a6eddbf4515316d08c
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
5.11
Status
affected
Version
0
Version <
5.11
Status
unaffected
Version <=
6.1.*
Version
6.1.189
Status
unaffected
Version <=
6.6.*
Version
6.6.151
Status
unaffected
Version <=
6.12.*
Version
6.12.101
Status
unaffected
Version <=
6.18.*
Version
6.18.42
Status
unaffected
Version <=
7.1.*
Version
7.1.6
Status
unaffected
Version <=
*
Version
7.2
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.63% | 0.47 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
https://git.kernel.org/stable/c/c6eb2d615210b80339548ab07c0230edaab9a6c7
https://git.kernel.org/stable/c/8ff78591d309c50a4fdab683b68dd8d512a270dd
https://git.kernel.org/stable/c/3bf0e349cbb4f975f35eb22753acc346b89c66a0
https://git.kernel.org/stable/c/37ff9794be48d0caa37687e04d09675f9c849121
https://git.kernel.org/stable/c/ffb2bd7ade36ec4da32c46a6eddbf4515316d08c
https://git.kernel.org/stable/c/c29affd44e6769e3073235d4b471d9b501fa8166