Use-after-free in Linux kernel - CVE-2026-74587
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to use-after-free in the SCTP ASCONF handling code when processing a delayed authenticated ASCONF-ACK after peer restart handling purges the ASCONF queue. A remote attacker can send a delayed authenticated ASCONF-ACK to cause a denial of service.
The issue occurs because a cached ASCONF chunk pointer can remain dangling while the association is still alive during peer restart handling.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-74587
linux (Debian package) - update to 6.12.105-1
External References
- https://git.kernel.org/stable/c/07daf4f9750104960a1d60831b2353c0d41f35fb
- https://git.kernel.org/stable/c/10459b03e2d9ee12435e96f587de4d4cacdbf435
- https://git.kernel.org/stable/c/179676f0166230c80053a392303485b37c93dd33
- https://git.kernel.org/stable/c/618b5c6d049896fcfabb91afc072954c92cb2693
- https://git.kernel.org/stable/c/8c283e7b56adce00193837f3311b06662466fb21
- https://git.kernel.org/stable/c/d949992bc3f00027a2c755e860a11950c75f6073
- https://git.kernel.org/stable/c/dc67d528c2fa939cec7fe3bf7f3089c8d281ca3d
- https://git.kernel.org/stable/c/e1bb114e09372fd6e03387ced9ef566da336ed6c