Incorrect calculation in Linux kernel - CVE-2026-72021
Published: August 16, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause incorrect connection state tracking.
The vulnerability exists due to improper calculation of buffer offsets in SCTP state lookup in net/netfilter/ipvs/ip_vs_proto_sctp.c when processing IPv6 SCTP packets with extension headers. A remote attacker can send a specially crafted IPv6 SCTP packet with extension headers to cause incorrect connection state tracking.
This can cause an SCTP connection to be moved to the established state before the SCTP handshake has completed, resulting in incorrect timeout handling and destination counter updates.
Affected software
How to mitigate CVE-2026-72021
External References
- https://git.kernel.org/stable/c/247d055504dcc852e539b9f7f30d19f9741474bf
- https://git.kernel.org/stable/c/290e9e8389b556efc603522e28bd1543846aa336
- https://git.kernel.org/stable/c/2f75c0faa3361b28e36cc0512b3299e163e25789
- https://git.kernel.org/stable/c/9cb5ac594ca76d3a71803b23b74c835b0721e628
- https://git.kernel.org/stable/c/9f94573ab962a9e81954b755da016fa3cd2f5039
- https://git.kernel.org/stable/c/a4a2d2e483d79cc2ad3a170674cf159644acf22b
- https://git.kernel.org/stable/c/d2b8b1557ec07ea1bb5dddbceaf4dfe63d388e27
- https://git.kernel.org/stable/c/e5d0bb8871668f20de8f3c94b5ae3f372346bc6e