Insufficient Session Expiration in Linux kernel - CVE-2026-80890
Published: September 5, 2026
Vulnerability details
The vulnerability allows a remote attacker to restart an SCTP association.
The vulnerability exists due to improper validation of cookie expiration in sctp_unpack_cookie() when processing an expired State Cookie for an existing association with mismatched Verification Tags. A remote attacker can replay an expired State Cookie with mismatched Verification Tags to restart an SCTP association.
Affected software
How to mitigate CVE-2026-80890
External References
- https://git.kernel.org/stable/c/35c279113498d19a8734e2aae67b951b9b20f634
- https://git.kernel.org/stable/c/61baa5020b0afb41bfd97f8f6ce5e336c4a4546e
- https://git.kernel.org/stable/c/817cffdbdbdf50e1f2b016599d1897de3ca54964
- https://git.kernel.org/stable/c/9d8da8e0a9bce4a340af60dd0446bc7eb8d07587
- https://git.kernel.org/stable/c/a0d1693923f41d6f49083aa2446686aed09d1d79
- https://git.kernel.org/stable/c/c151daba0ceb1fb068a215b07de89fb1eb5f87bc
- https://git.kernel.org/stable/c/c68557a49e960dbcdede22c7a9b488603078b8b4
- https://git.kernel.org/stable/c/f6e3cc296372accad4ee57405195021231ef4bcb