9.8

CVE-2026-74587

sctp: fix use-after-free of cached ASCONF chunk

In the Linux kernel, the following vulnerability has been resolved:

sctp: fix use-after-free of cached ASCONF chunk

addip_last_asconf caches the outstanding outbound ASCONF chunk. The normal
ASCONF-ACK completion path releases the chunk and clears the pointer.

However, sctp_asconf_queue_teardown() releases the cached chunk without
clearing addip_last_asconf. During peer restart handling,
sctp_sf_do_dupcook_a() queues SCTP_CMD_PURGE_ASCONF_QUEUE, which invokes
sctp_asconf_queue_teardown() while the association remains alive and leaves
the pointer dangling.

A delayed authenticated ASCONF-ACK can then reach sctp_sf_do_asconf_ack(),
which accesses the stale chunk and passes it to sctp_process_asconf_ack(),
causing a use-after-free and a second release.

Clearing the pointer exposes a race with T4 expiry. Peer restart handling
queues the timer stop before the purge, but SCTP_CMD_TIMER_STOP uses
timer_delete(), which does not wait for a callback already running on
another CPU. Such a callback can reach sctp_sf_t4_timer_expire() after
the purge and dereference NULL.

Clear addip_last_asconf after releasing the cached chunk, and make
sctp_sf_t4_timer_expire() consume a stale T4 expiry if no outstanding
ASCONF remains.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version a000c01e60e40e15304ffe48fff051d17a7bea91
Version < 10459b03e2d9ee12435e96f587de4d4cacdbf435
Status affected
Version a000c01e60e40e15304ffe48fff051d17a7bea91
Version < e1bb114e09372fd6e03387ced9ef566da336ed6c
Status affected
Version a000c01e60e40e15304ffe48fff051d17a7bea91
Version < 179676f0166230c80053a392303485b37c93dd33
Status affected
Version a000c01e60e40e15304ffe48fff051d17a7bea91
Version < dc67d528c2fa939cec7fe3bf7f3089c8d281ca3d
Status affected
Version a000c01e60e40e15304ffe48fff051d17a7bea91
Version < 618b5c6d049896fcfabb91afc072954c92cb2693
Status affected
Version a000c01e60e40e15304ffe48fff051d17a7bea91
Version < 07daf4f9750104960a1d60831b2353c0d41f35fb
Status affected
Version a000c01e60e40e15304ffe48fff051d17a7bea91
Version < d949992bc3f00027a2c755e860a11950c75f6073
Status affected
Version a000c01e60e40e15304ffe48fff051d17a7bea91
Version < 8c283e7b56adce00193837f3311b06662466fb21
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 3.0
Status affected
Version 0
Version < 3.0
Status unaffected
Version <= 5.10.*
Version 5.10.265
Status unaffected
Version <= 5.15.*
Version 5.15.216
Status unaffected
Version <= 6.1.*
Version 6.1.183
Status unaffected
Version <= 6.6.*
Version 6.6.152
Status unaffected
Version <= 6.12.*
Version 6.12.104
Status unaffected
Version <= 6.18.*
Version 6.18.45
Status unaffected
Version <= 7.1.*
Version 7.1.9
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.18% 0.072
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/07daf4f9750104960a1d60831b2353c0d41f35fb
https://git.kernel.org/stable/c/10459b03e2d9ee12435e96f587de4d4cacdbf435
https://git.kernel.org/stable/c/179676f0166230c80053a392303485b37c93dd33
https://git.kernel.org/stable/c/618b5c6d049896fcfabb91afc072954c92cb2693
https://git.kernel.org/stable/c/8c283e7b56adce00193837f3311b06662466fb21
https://git.kernel.org/stable/c/d949992bc3f00027a2c755e860a11950c75f6073
https://git.kernel.org/stable/c/dc67d528c2fa939cec7fe3bf7f3089c8d281ca3d
https://git.kernel.org/stable/c/e1bb114e09372fd6e03387ced9ef566da336ed6c