{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-64564","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-07-19T15:36:31.797Z","datePublished":"2026-08-04T06:23:23.339Z","dateUpdated":"2026-08-09T03:38:13.350Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-09T03:38:13.350Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: don't free the ASCONF's own transport in DEL-IP processing\n\nsctp_process_asconf() caches the transport the ASCONF chunk is processed\nagainst in asconf->transport (== chunk->transport, set once in sctp_rcv()).\nFor an ASCONF located through its Address Parameter by\n__sctp_rcv_asconf_lookup(), that cached transport corresponds to the\nAddress Parameter, which need not be the packet's source address.\n\nsctp_process_asconf_param() rejects a DEL-IP for the packet source address\n(ADDIP D8, SCTP_ERROR_DEL_SRC_IP), but nothing protects asconf->transport.\nA single ASCONF can therefore carry, in order:\n\n    [Address Parameter L] [DEL-IP L] [DEL-IP 0.0.0.0]\n\nwhere L differs from the source. The DEL-IP for L passes the D8 check and\ncalls sctp_assoc_rm_peer() on the transport that asconf->transport still\npoints at, freeing it (RCU-deferred). The following wildcard DEL-IP then\nreuses the now-dangling asconf->transport in sctp_assoc_set_primary() and\nsctp_assoc_del_nonprimary_peers(): set_primary() dereferences the freed\ntransport (->ipaddr, ->state) and plants the dangling pointer into\nasoc->peer.primary_path / active_path, and del_nonprimary_peers(), keeping\nonly the pointer that is no longer on the list, removes every real\ntransport, leaving the association with a transport_count of 0 and\nprimary_path/active_path pointing at freed memory.\n\nReject a DEL-IP that targets the transport the ASCONF is being processed\nagainst, mirroring the existing source-address guard, so the wildcard\nbranch can never reuse a freed transport."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL"},"scenarios":[{"lang":"en","value":"AV:N - The bug is in SCTP ASCONF receive processing (sctp_rcv → sctp_sf_do_asconf → sctp_process_asconf → sctp_process_asconf_param); a remote peer triggers it by sending a crafted ASCONF over IP/IPv6 on an established association, matching kernel guidance that net/ stack bugs reachable via received packets are Network.\nAC:L - A single attacker-controlled ASCONF with [Address Parameter L][DEL-IP L][DEL-IP 0.0.0.0] reliably frees asconf->transport then reuses it in the same softirq; the peer fully controls multi-homing, serial, and parameter order, with no race or other condition outside attacker influence.\nPR:N - Any remote SCTP peer that completes a normal association with ADD-IP negotiated can send the ASCONF; SCTP-AUTH keys come from the handshake the peer itself performs (or addip_noauth), and no local credentials or capabilities on the target are required.\nUI:N - Exploitation requires only attacker-sent SCTP packets processed automatically in the receive/state-machine path; no victim user action such as opening a file or mounting a device is needed.\nS:U - Impact is confined to the vulnerable host kernel (sctp_transport UAF / crash or privilege escalation) and does not cross a VM, IOMMU, or other security-authority boundary.\nC:H - This is a heap use-after-free of an sctp_transport planted into primary_path/active_path after RCU-deferred free; freed-object reuse yields arbitrary kernel read primitives, scored High per UAF guidance.\nI:H - The same transport UAF enables heap spraying and write/control-flow hijacking via later dereferences of the dangling primary_path/active_path, so integrity impact is High.\nA:H - set_primary() immediately dereferences the freed transport and leaves the association with transport_count 0 and dangling path pointers, causing a reproducible kernel oops/panic on subsequent use, which is High availability impact."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/sctp/sm_make_chunk.c"],"versions":[{"version":"42e30bf3463cd37d73839376662cb79b4d5c416c","lessThan":"fedeb4468987bcaff85fe3061de5ae052d414740","status":"affected","versionType":"git"},{"version":"42e30bf3463cd37d73839376662cb79b4d5c416c","lessThan":"74e8f3e7114f0e26d1b2c4c048044db9fcc27603","status":"affected","versionType":"git"},{"version":"42e30bf3463cd37d73839376662cb79b4d5c416c","lessThan":"85aca407c560aba81b5ce9d3d6cf94c74077d19b","status":"affected","versionType":"git"},{"version":"42e30bf3463cd37d73839376662cb79b4d5c416c","lessThan":"d136b29bf91dd8e3161281b87de597b7311d9462","status":"affected","versionType":"git"},{"version":"42e30bf3463cd37d73839376662cb79b4d5c416c","lessThan":"9b2854f86f0b56e9027d68e7a3fc909d1a9b566f","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/sctp/sm_make_chunk.c"],"versions":[{"version":"2.6.25","status":"affected"},{"version":"0","lessThan":"2.6.25","status":"unaffected","versionType":"semver"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.1.6","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"},{"version":"7.2-rc5","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.25","versionEndExcluding":"6.6.148"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.25","versionEndExcluding":"6.12.101"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.25","versionEndExcluding":"6.18.42"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.25","versionEndExcluding":"7.1.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.25","versionEndExcluding":"7.2-rc5"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/fedeb4468987bcaff85fe3061de5ae052d414740"},{"url":"https://git.kernel.org/stable/c/74e8f3e7114f0e26d1b2c4c048044db9fcc27603"},{"url":"https://git.kernel.org/stable/c/85aca407c560aba81b5ce9d3d6cf94c74077d19b"},{"url":"https://git.kernel.org/stable/c/d136b29bf91dd8e3161281b87de597b7311d9462"},{"url":"https://git.kernel.org/stable/c/9b2854f86f0b56e9027d68e7a3fc909d1a9b566f"},{"url":"https://matrix.tencent.com/en/2026/08/06/sctphantom-CVE-2026-64564"}],"title":"sctp: don't free the ASCONF's own transport in DEL-IP processing","x_generator":{"engine":"bippy-1.2.0"}},"adp":[{"title":"CVE Program Container","references":[{"url":"http://www.openwall.com/lists/oss-security/2026/08/06/3"},{"url":"http://www.openwall.com/lists/oss-security/2026/08/06/4"},{"url":"http://www.openwall.com/lists/oss-security/2026/08/06/13"},{"url":"http://www.openwall.com/lists/oss-security/2026/08/07/1"},{"url":"http://www.openwall.com/lists/oss-security/2026/08/07/2"},{"url":"http://www.openwall.com/lists/oss-security/2026/08/07/8"}],"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2026-08-08T01:31:36.501Z"}}]}}