{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89478","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.711Z","datePublished":"2026-09-11T19:43:34.588Z","dateUpdated":"2026-09-14T12:00:14.944Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-14T12:00:14.944Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: drop a chunk if its transport was removed\n\nsctp_rcv() resolves the transport once per packet and leaves it in\nchunk->transport. The lookup reference, or the one sctp_add_backlog() takes\nif the socket is owned by userspace, keeps it around until the chunk has\nbeen processed.\n\nAn authenticated ASCONF DEL-IP can remove it in the meantime.\nsctp_assoc_rm_peer() takes the transport out of the association and calls\nsctp_transport_free(), which tags it dead and drops the reference the\nassociation held. There is a window on both paths: the packet can sit on\nthe socket backlog, and on the direct path the lookup completes before\nbh_lock_sock().\n\nThe DATA chunk in that packet puts the removed transport back into\nasoc->peer.last_data_from. Once the packet is done that reference goes\naway and the transport is freed by RCU, so the next delayed SACK carries\nthe pointer into the SACK chunk and sctp_outq_select_transport() reads the\nfreed transport's state.\n\nDrop the chunk in sctp_inq_push(), next to the existing rcvr->dead check.\nBoth paths reach it with the association's socket lock held. The peer\nretransmits it."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL"},"scenarios":[{"lang":"en","value":"AV:N - A remote SCTP peer reaches the bug via received packets in sctp_rcv() on internet-facing SCTP servers and telecom endpoints; DATA that already resolved a transport is processed after an authenticated ASCONF DEL-IP (or COOKIE-ECHO restart) has removed that peer.\nAC:L - The attacker controls both sides of the race by sending ASCONF DEL-IP (or a restart that calls sctp_assoc_rm_peer) and a DATA chunk whose lookup already holds the doomed transport; the backlog path is FIFO-deterministic while the socket is in a syscall, and the direct path is a bh_lock_sock race the attacker creates.\nPR:N - Exploitation requires only a network-reachable established SCTP association; no local Linux credentials, capabilities, or namespaces are needed, and SCTP-AUTH keys used for ASCONF come from the handshake the peer itself performs.\nUI:N - Inbound SCTP packets are processed automatically in softirq or socket backlog on a listening or already-associated endpoint; no victim user action such as opening a file or mounting a device is required.\nS:U - Impact is kernel memory corruption and potential privilege escalation within the host SCTP stack; it does not cross a VM, IOMMU, or other security-authority boundary.\nC:H - DATA processing plants the removed transport into asoc->peer.last_data_from; after the lookup reference is dropped the object is RCU-freed, and the next delayed SACK dereferences the freed sctp_transport in sctp_outq_select_transport(), a UAF that enables arbitrary kernel disclosure via heap grooming.\nI:H - sctp_outq_select_transport() does list_add_tail() into the freed send_ready field, and sctp_packet_config()/sctp_transport_burst_limited() write vtag, pathmtu, cwnd, and burst_limited into the reclaimed slab object, yielding arbitrary write and control-flow hijack primitives.\nA:H - Dereferencing the freed transport during delayed SACK transmission can immediately oops or panic the kernel, and the UAF can be triggered repeatedly by a malicious SCTP peer."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/sctp/inqueue.c"],"versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"3fc072e7cb4a0ff251d13cfc2d24f62489cd9386","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"d7cb5ad832095dc4becfdb2a36007ffd50e49fb0","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"0422b092a3d43ca462932ff9f747731ca078d1d4","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"928fd7920ba37cc5637a211b9be979083413a2fa","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"c6c86a5e62a4fec36692ddd64b9144b660f71f96","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"1035bdef1efb9b1076d1a57b81e08c637ff08ecc","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"3537961df2163258bddc230db0e18dc14e925ea6","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"03a9d10ecf71f54b2af8020935f2033d4a132be5","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/sctp/inqueue.c"],"versions":[{"version":"2.6.12","status":"affected"},{"version":"0","lessThan":"2.6.12","status":"unaffected","versionType":"semver"},{"version":"5.10.270","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.221","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.109","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"5.10.270"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"5.15.221"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"6.12.109"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/3fc072e7cb4a0ff251d13cfc2d24f62489cd9386"},{"url":"https://git.kernel.org/stable/c/d7cb5ad832095dc4becfdb2a36007ffd50e49fb0"},{"url":"https://git.kernel.org/stable/c/0422b092a3d43ca462932ff9f747731ca078d1d4"},{"url":"https://git.kernel.org/stable/c/928fd7920ba37cc5637a211b9be979083413a2fa"},{"url":"https://git.kernel.org/stable/c/c6c86a5e62a4fec36692ddd64b9144b660f71f96"},{"url":"https://git.kernel.org/stable/c/1035bdef1efb9b1076d1a57b81e08c637ff08ecc"},{"url":"https://git.kernel.org/stable/c/3537961df2163258bddc230db0e18dc14e925ea6"},{"url":"https://git.kernel.org/stable/c/03a9d10ecf71f54b2af8020935f2033d4a132be5"}],"title":"sctp: drop a chunk if its transport was removed","x_generator":{"engine":"bippy-1.2.0"}}}}