Vulnerabilities
- CVSS
- 9.8 Critical
- Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H- Risk score
- 78.4
- Published
- 2026-08-04
- Status
- Received
In the Linux kernel, the following vulnerability has been resolved:
sctp: don't free the ASCONF's own transport in DEL-IP processing
sctp_process_asconf() caches the transport the ASCONF chunk is processed
against in asconf->transport (== chunk->transport, set once in sctp_rcv()).
For an ASCONF located through its Address Parameter by
__sctp_rcv_asconf_lookup(), that cached transport corresponds to the
Address Parameter, which need not be the packet's source address.
sctp_process_asconf_param() rejects a DEL-IP for the packet source address
(ADDIP D8, SCTP_ERROR_DEL_SRC_IP), but nothing protects asconf->transport.
A single ASCONF can therefore carry, in order:
[Address Parameter L] [DEL-IP L] [DEL-IP 0.0.0.0]
where L differs from the source. The DEL-IP for L passes the D8 check and
calls sctp_assoc_rm_peer() on the transport that asconf->transport still
points at, freeing it (RCU-deferred). The following wildcard DEL-IP then
reuses the now-dangling asconf->transport in sctp_assoc_set_primary() and
sctp_assoc_del_nonprimary_peers(): set_primary() dereferences the freed
transport (->ipaddr, ->state) and plants the dangling pointer into
asoc->peer.primary_path / active_path, and del_nonprimary_peers(), keeping
only the pointer that is no longer on the list, removes every real
transport, leaving the association with a transport_count of 0 and
primary_path/active_path pointing at freed memory.
Reject a DEL-IP that targets the transport the ASCONF is being processed
against, mirroring the existing source-address guard, so the wildcard
branch can never reuse a freed transport.
Coverage 6
threat-intel
Multiple vulnerabilities have been discovered in the Linux kernel of Debian LTS. These vulnerabilities allow for privilege escalation, data compromise, and denial of service. The affected systems include Debian 12 Bookwo…
threat-intel
Multiple vulnerabilities have been discovered in the Linux kernel of SUSE. Several of these vulnerabilities allow for privilege escalation, data confidentiality breaches, and data integrity issues. These vulnerabilities…
vulnerability
Multiple vulnerabilities have been discovered in the Linux kernel of Debian. These vulnerabilities allow for privilege escalation, data compromise, and denial of service. Affected Debian versions are those prior to 6.12.…
threat-intel
Multiple vulnerabilities have been discovered in the SUSE Linux kernel. Several of these vulnerabilities can lead to privilege escalation, denial of service, and data confidentiality breaches. The vulnerabilities are bei…
ransomware
This week’s security news is dominated by AI-related threats, including a vulnerability exploited in Metabase, a new Shai-Hulud worm leveraging the MCP Registry, and a Chinese review of Palo Alto Networks. Alongside the…

vulnerability
A 18-year-old vulnerability in Linux's SCTP networking code allows local users to gain root access on a host, potentially escaping containers. Tencent researchers discovered and demonstrated this flaw, which has existed…

Advisories and references