9.8

CVE-2026-89478

sctp: drop a chunk if its transport was removed

In the Linux kernel, the following vulnerability has been resolved:

sctp: drop a chunk if its transport was removed

sctp_rcv() resolves the transport once per packet and leaves it in
chunk->transport. The lookup reference, or the one sctp_add_backlog() takes
if the socket is owned by userspace, keeps it around until the chunk has
been processed.

An authenticated ASCONF DEL-IP can remove it in the meantime.
sctp_assoc_rm_peer() takes the transport out of the association and calls
sctp_transport_free(), which tags it dead and drops the reference the
association held. There is a window on both paths: the packet can sit on
the socket backlog, and on the direct path the lookup completes before
bh_lock_sock().

The DATA chunk in that packet puts the removed transport back into
asoc->peer.last_data_from. Once the packet is done that reference goes
away and the transport is freed by RCU, so the next delayed SACK carries
the pointer into the SACK chunk and sctp_outq_select_transport() reads the
freed transport's state.

Drop the chunk in sctp_inq_push(), next to the existing rcvr->dead check.
Both paths reach it with the association's socket lock held. The peer
retransmits it.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 3fc072e7cb4a0ff251d13cfc2d24f62489cd9386
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < d7cb5ad832095dc4becfdb2a36007ffd50e49fb0
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 0422b092a3d43ca462932ff9f747731ca078d1d4
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 928fd7920ba37cc5637a211b9be979083413a2fa
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < c6c86a5e62a4fec36692ddd64b9144b660f71f96
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 1035bdef1efb9b1076d1a57b81e08c637ff08ecc
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 3537961df2163258bddc230db0e18dc14e925ea6
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 03a9d10ecf71f54b2af8020935f2033d4a132be5
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 2.6.12
Status affected
Version 0
Version < 2.6.12
Status unaffected
Version <= 5.10.*
Version 5.10.270
Status unaffected
Version <= 5.15.*
Version 5.15.221
Status unaffected
Version <= 6.1.*
Version 6.1.188
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.109
Status unaffected
Version <= 6.18.*
Version 6.18.50
Status unaffected
Version <= 7.2.*
Version 7.2.4
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.46% 0.388
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/c6c86a5e62a4fec36692ddd64b9144b660f71f96
https://git.kernel.org/stable/c/1035bdef1efb9b1076d1a57b81e08c637ff08ecc
https://git.kernel.org/stable/c/3537961df2163258bddc230db0e18dc14e925ea6
https://git.kernel.org/stable/c/03a9d10ecf71f54b2af8020935f2033d4a132be5
https://git.kernel.org/stable/c/0422b092a3d43ca462932ff9f747731ca078d1d4
https://git.kernel.org/stable/c/3fc072e7cb4a0ff251d13cfc2d24f62489cd9386
https://git.kernel.org/stable/c/928fd7920ba37cc5637a211b9be979083413a2fa
https://git.kernel.org/stable/c/d7cb5ad832095dc4becfdb2a36007ffd50e49fb0