Use-after-free in Linux kernel - CVE-2026-74688
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to use-after-free in the SCTP control chunk handling logic when transmitting a queued HEARTBEAT ACK after the associated peer transport has been removed. A remote attacker can trigger peer transport removal while a control chunk retains a stale transport pointer to cause a denial of service.
The issue occurs when src_out_of_asoc_ok is enabled and the HEARTBEAT ACK remains queued on control_chunk_list instead of being transmitted immediately.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-74688
linux (Debian package) - update to 6.12.105-1
External References
- https://git.kernel.org/stable/c/18d704bdd809377dfd81a3c2f42426763b5da227
- https://git.kernel.org/stable/c/4d6b9cac6df5e0cfef1a66b3edd7aebdb9e4b7e7
- https://git.kernel.org/stable/c/6160e756db81d6cb63e3e2952efcf6c5134be385
- https://git.kernel.org/stable/c/8de65194a04d2552cd39b6c67d942d490f22d174
- https://git.kernel.org/stable/c/936658ec41c28c397ef390140e02d4c91ade92f0
- https://git.kernel.org/stable/c/c9158ceaf27780ef64534ad72f44ffde3f8ccc49
- https://git.kernel.org/stable/c/dbb3f418a8665ffb0514e1a9520ab6a1c5d4d886
- https://git.kernel.org/stable/c/fad4766a74220fe579c6fcaa10ba01c23529814f