SB2026090552 - Insufficient Session Expiration in Linux kernel sctp
Published: September 5, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Insufficient Session Expiration (CVE-ID: CVE-2026-80890)
CWE-ID: CWE-613 - Insufficient Session Expiration
CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to restart an SCTP association.
The vulnerability exists due to improper validation of cookie expiration in sctp_unpack_cookie() when processing an expired State Cookie for an existing association with mismatched Verification Tags. A remote attacker can replay an expired State Cookie with mismatched Verification Tags to restart an SCTP association.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/35c279113498d19a8734e2aae67b951b9b20f634
- https://git.kernel.org/stable/c/61baa5020b0afb41bfd97f8f6ce5e336c4a4546e
- https://git.kernel.org/stable/c/817cffdbdbdf50e1f2b016599d1897de3ca54964
- https://git.kernel.org/stable/c/9d8da8e0a9bce4a340af60dd0446bc7eb8d07587
- https://git.kernel.org/stable/c/a0d1693923f41d6f49083aa2446686aed09d1d79
- https://git.kernel.org/stable/c/c151daba0ceb1fb068a215b07de89fb1eb5f87bc
- https://git.kernel.org/stable/c/c68557a49e960dbcdede22c7a9b488603078b8b4
- https://git.kernel.org/stable/c/f6e3cc296372accad4ee57405195021231ef4bcb