SB20260812378 - Use-after-free in Linux kernel sctp
Published: August 12, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Use-after-free (CVE-ID: CVE-2026-68162)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in the SCTP auth_enable sysctl handler when handling writes to an already opened sysctl file during network namespace teardown. A local user can write to the auth_enable sysctl entry to cause a denial of service.
The issue is exposed during initialization before the SCTP control socket exists and during teardown after the control socket has been released.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/19573dcddb8819fd68d6cd1f916c1c99c3fa4ff4
- https://git.kernel.org/stable/c/626bda8cfe43dff19a9833ff6ba055a817b5455c
- https://git.kernel.org/stable/c/66700c0719675e0e118ae83b2d7168dacd69dd3d
- https://git.kernel.org/stable/c/a50e73488e0bbdd262b3be3c9a1d8dd078382381
- https://git.kernel.org/stable/c/be6aae9d1b91c603adb35872d37d40e83daf8758
- https://git.kernel.org/stable/c/f8d5e7846025f4ab15a461235f8ebae9094a361a