SB20260812377 - Improper resource shutdown or release in Linux kernel sctp
Published: August 12, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper resource shutdown or release (CVE-ID: CVE-2026-68161)
CWE-ID: CWE-404 - Improper Resource Shutdown or Release
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper resource shutdown in SCTP UDP tunnel sockets during net namespace teardown when tearing down a network namespace with SCTP UDP tunneling enabled. A local user can trigger namespace teardown while the sockets remain installed to cause a denial of service.
Only systems using per-network-namespace SCTP UDP tunneling are affected.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/37ff9794be48d0caa37687e04d09675f9c849121
- https://git.kernel.org/stable/c/3bf0e349cbb4f975f35eb22753acc346b89c66a0
- https://git.kernel.org/stable/c/8ff78591d309c50a4fdab683b68dd8d512a270dd
- https://git.kernel.org/stable/c/c6eb2d615210b80339548ab07c0230edaab9a6c7
- https://git.kernel.org/stable/c/ffb2bd7ade36ec4da32c46a6eddbf4515316d08c