7.8

CVE-2026-68162

sctp: avoid auth_enable sysctl UAF during netns teardown

In the Linux kernel, the following vulnerability has been resolved:

sctp: avoid auth_enable sysctl UAF during netns teardown

proc_sctp_do_auth() updates the SCTP control socket after changing
net.sctp.auth_enable. The handler gets the per-net SCTP state from
ctl->data, so an already opened sysctl file can still target a network
namespace while that namespace is being torn down.

SCTP previously registered its per-net sysctls from sctp_defaults_init(),
while the control socket is created later from sctp_ctrlsock_init(). This
exposed a window during initialization where auth_enable was writable
before net->sctp.ctl_sock existed, and a teardown window where auth_enable
stayed writable after inet_ctl_sock_destroy() had released the control
socket.

Move the per-net SCTP sysctl registration into sctp_ctrlsock_init() after
sctp_ctl_sock_init() succeeds, and unregister the sysctl table before
destroying the control socket in sctp_ctrlsock_exit(). If sysctl
registration fails after the control socket was created, destroy the
control socket in the same init path.

Make sctp_sysctl_net_unregister() tolerate a missing header and clear the
saved pointer so init-error and exit paths can safely share the unregister
helper.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 10c869a52f266e40f548cc3c565d14930a5edafc
Version < 19573dcddb8819fd68d6cd1f916c1c99c3fa4ff4
Status affected
Version dc583e7e5f8515ca489c0df28e4362a70eade382
Version < ceb7190b5c873d4a1267a1600c5aa52c600e929f
Status affected
Version bd2a2939423566c654545fa3e96a656662a0af9e
Version < fd66854a22661929245f3d2b244c432bc8b1a150
Status affected
Version 1b67030d39f2b00f94ac1f0af11ba6657589e4d3
Version < 158f3cc332dc53f43ec20060233d7c3cecd6d912
Status affected
Version 7ec30c54f339c640aa7e49d7e9f7bbed6bd42bf6
Version < 66700c0719675e0e118ae83b2d7168dacd69dd3d
Status affected
Version c184bc621e3cef03ac9ba81a50dda2dae6a21d36
Version < 626bda8cfe43dff19a9833ff6ba055a817b5455c
Status affected
Version 15649fd5415eda664ef35780c2013adeb5d9c695
Version < be6aae9d1b91c603adb35872d37d40e83daf8758
Status affected
Version 15649fd5415eda664ef35780c2013adeb5d9c695
Version < a50e73488e0bbdd262b3be3c9a1d8dd078382381
Status affected
Version 15649fd5415eda664ef35780c2013adeb5d9c695
Version < f8d5e7846025f4ab15a461235f8ebae9094a361a
Status affected
Version 5.4.290
Version < 5.4.292
Status affected
Version 5.10.234
Version < 5.10.266
Status affected
Version 5.15.177
Version < 5.15.217
Status affected
Version 6.1.125
Version < 6.1.184
Status affected
Version 6.6.72
Version < 6.6.151
Status affected
Version 6.12.10
Version < 6.12.101
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.13
Status affected
Version 0
Version < 6.13
Status unaffected
Version <= 5.4.*
Version 5.4.292
Status unaffected
Version <= 5.10.*
Version 5.10.266
Status unaffected
Version <= 5.15.*
Version 5.15.217
Status unaffected
Version <= 6.1.*
Version 6.1.184
Status unaffected
Version <= 6.6.*
Version 6.6.151
Status unaffected
Version <= 6.12.*
Version 6.12.101
Status unaffected
Version <= 6.18.*
Version 6.18.42
Status unaffected
Version <= 7.1.*
Version 7.1.6
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.061
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/19573dcddb8819fd68d6cd1f916c1c99c3fa4ff4
https://git.kernel.org/stable/c/66700c0719675e0e118ae83b2d7168dacd69dd3d
https://git.kernel.org/stable/c/626bda8cfe43dff19a9833ff6ba055a817b5455c
https://git.kernel.org/stable/c/be6aae9d1b91c603adb35872d37d40e83daf8758
https://git.kernel.org/stable/c/a50e73488e0bbdd262b3be3c9a1d8dd078382381
https://git.kernel.org/stable/c/f8d5e7846025f4ab15a461235f8ebae9094a361a
https://git.kernel.org/stable/c/158f3cc332dc53f43ec20060233d7c3cecd6d912
https://git.kernel.org/stable/c/ceb7190b5c873d4a1267a1600c5aa52c600e929f
https://git.kernel.org/stable/c/fd66854a22661929245f3d2b244c432bc8b1a150