Use-after-free in Linux kernel - CVE-2026-72383
Published: August 16, 2026
Vulnerability details
The vulnerability allows a local attacker to cause a denial of service.
The vulnerability exists due to use-after-free in sctp_free_addr_wq() and sctp_addr_wq_timeout_handler() when handling addr_wq_timer teardown. A local attacker can trigger a race condition to cause a denial of service.
The issue arises because a timer handler may continue running after the associated wait queue has been freed.
Affected software
Ubuntu
linux-nvidia-tegra (Ubuntu package)
How to mitigate CVE-2026-72383
linux-nvidia-tegra (Ubuntu package) - update to 6.8.0-1035.38