SB20260912307 - Use-after-free in Linux kernel sctp



SB20260912307 - Use-after-free in Linux kernel sctp

Published: September 12, 2026 Updated: October 1, 2026

Security Bulletin ID SB20260912307
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Use-after-free (CVE-ID: CVE-2026-89479)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to access freed memory.

The vulnerability exists due to use-after-free in the SCTP endpoint receive loop when processing a specially crafted SCTP packet containing bundled chunks. A remote attacker can send an SCTP packet that deletes an association before subsequent chunks are processed to access freed memory.

Exploitation requires the packet to be processed from the socket backlog in task context.


Remediation

Install update from vendor's website.