← All Advisories

Linux Kernel SCTP Teardown Path Frees the Cached Outbound ASCONF Chunk Without Clearing the Cache Pointer, Exposing a Use-After-Free

Last refreshed2026-09-28

Status: NEW  |  Advisory ID: CVE-2026-74587

Key Details

CVECVE-2026-74587
CVSS Score / Version9.8 (Critical) / CVSS v3.1
Updated2026-08-25
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.

What to Know

In the Linux kernel, the following vulnerability has been resolved:

sctp: fix use-after-free of cached ASCONF chunk

addip_last_asconf caches the outstanding outbound ASCONF chunk. The normal

ASCONF-ACK completion path releases the chunk and clears the pointer.

However, sctp_asconf_queue_teardown() releases the cached chunk without

clearing addip_last_asconf. During peer restart handling,

sctp_sf_do_dupcook_a() queues SCTP_CMD_PURGE_ASCONF_QUEUE, which invokes

sctp_asconf_queue_teardown() while the association remains alive and leaves

the pointer dangling.

A delayed authenticated ASCONF-ACK can then reach sctp_sf_do_asconf_ack(),

which accesses the stale chunk and passes it to sctp_process_asconf_ack(),

causing a use-after-free and a second release.

Clearing the pointer exposes a race with T4 expiry. Peer restart handling

queues the timer stop before the purge, but SCTP_CMD_TIMER_STOP uses

timer_delete(), which does not wait for a callback already running on

another CPU. Such a callback can reach sctp_sf_t4_timer_expire() after

the purge and dereference NULL.

Clear addip_last_asconf after releasing the cached chunk, and make

sctp_sf_t4_timer_expire() consume a stale T4 expiry if no outstanding

ASCONF remains. (NVD)

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-74587
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-74587