-

CVE-2026-80890

Medienbericht

sctp: reject stale cookies with mismatched verification tags

In the Linux kernel, the following vulnerability has been resolved:

sctp: reject stale cookies with mismatched verification tags

sctp_unpack_cookie() skips cookie expiration checks whenever an
association already exists.  This is broader than the exception in
RFC 9260 Section 5.2.4.

For an existing association, Section 5.2.4 permits an expired State
Cookie only when both Verification Tags in the cookie match the current
association.  Otherwise, the packet SHOULD be discarded and a Stale
Cookie ERROR MUST be sent.

The broad check lets an expired Action A restart cookie reach
sctp_sf_do_dupcook_a().  In a runtime test with the default 60 second
cookie lifetime, replaying such a cookie after 65 seconds returned a
COOKIE-ACK and restarted the association.

Check cookie expiration unless both Verification Tags match.  This
preserves the Action D exception for a lost COOKIE ACK while rejecting
expired cookies in all other cases.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < f6e3cc296372accad4ee57405195021231ef4bcb
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < c151daba0ceb1fb068a215b07de89fb1eb5f87bc
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 817cffdbdbdf50e1f2b016599d1897de3ca54964
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 61baa5020b0afb41bfd97f8f6ce5e336c4a4546e
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < c68557a49e960dbcdede22c7a9b488603078b8b4
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < a0d1693923f41d6f49083aa2446686aed09d1d79
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 35c279113498d19a8734e2aae67b951b9b20f634
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 9d8da8e0a9bce4a340af60dd0446bc7eb8d07587
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 2.6.12
Status affected
Version 0
Version < 2.6.12
Status unaffected
Version <= 5.10.*
Version 5.10.265
Status unaffected
Version <= 5.15.*
Version 5.15.216
Status unaffected
Version <= 6.1.*
Version 6.1.183
Status unaffected
Version <= 6.6.*
Version 6.6.151
Status unaffected
Version <= 6.12.*
Version 6.12.103
Status unaffected
Version <= 6.18.*
Version 6.18.44
Status unaffected
Version <= 7.1.*
Version 7.1.8
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.18% 0.073
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
08.09.2026 20:38
https://git.kernel.org/stable/c/f6e3cc296372accad4ee57405195021231ef4bcb
https://git.kernel.org/stable/c/c151daba0ceb1fb068a215b07de89fb1eb5f87bc
https://git.kernel.org/stable/c/817cffdbdbdf50e1f2b016599d1897de3ca54964
https://git.kernel.org/stable/c/61baa5020b0afb41bfd97f8f6ce5e336c4a4546e
https://git.kernel.org/stable/c/c68557a49e960dbcdede22c7a9b488603078b8b4
https://git.kernel.org/stable/c/a0d1693923f41d6f49083aa2446686aed09d1d79
https://git.kernel.org/stable/c/35c279113498d19a8734e2aae67b951b9b20f634
https://git.kernel.org/stable/c/9d8da8e0a9bce4a340af60dd0446bc7eb8d07587