SB20260824250 - Use-after-free in Linux kernel sctp
Published: August 24, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Use-after-free (CVE-ID: CVE-2026-74586)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to use-after-free in SCTP ASCONF handling when processing an authenticated ASCONF chunk that adds and removes a peer transport in the same chunk. A remote user can send a specially crafted authenticated ASCONF message to cause a denial of service.
The issue occurs because a stale new_transport pointer can be used when a queued HEARTBEAT is later processed during local address replacement.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/163847552a571bd55094291f4ffcdc1de0f14a7b
- https://git.kernel.org/stable/c/291accf36febce751021888de5f15090f4875b56
- https://git.kernel.org/stable/c/31efa656cf6aface26e88f038c14f22ee6ca1500
- https://git.kernel.org/stable/c/3b539b317cd052236fed0350364ff1268996ba46
- https://git.kernel.org/stable/c/beb33f8ee1ca83acddb2a5ae80f3d22ec550b4c3
- https://git.kernel.org/stable/c/c0f973bb5118dd1b146cda3fcc8af6f6057befec
- https://git.kernel.org/stable/c/ca33df36aa0143a1d04f57d2086020c12e7eddb7
- https://git.kernel.org/stable/c/db9d8e3b670f841755bc2018f178472dc6064d27