Description
In the Linux kernel, the following vulnerability has been resolved:

sctp: fix addr_wq_timer race in sctp_free_addr_wq()

sctp_free_addr_wq() previously removed addr_wq_timer using timer_delete()
while holding addr_wq_lock. However, timer_delete() does not guarantee that
a currently running timer handler has completed.

This allows a race with sctp_addr_wq_timeout_handler(), where the handler
may still run after addr_waitq has been freed, acquire addr_wq_lock, and
access freed memory, leading to a use-after-free.

Fix this by calling timer_shutdown_sync() before taking addr_wq_lock. This
guarantees that any in-flight timer handler has finished and prevents the
timer from being re-armed during teardown, making subsequent cleanup safe.
Published: 2026-08-15
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

sctp_free_addr_wq() removed its timer using timer_delete() while holding the address workqueue lock. Because timer_delete() does not guarantee that a timer handler finished, another thread running sctp_addr_wq_timeout_handler() could still execute after the workqueue has been freed, acquire the lock and dereference freed memory. This race creates a use‑after‑free that an attacker could exploit to execute arbitrary code with kernel privileges, potentially raising to full system control.

Affected Systems

All Linux kernel builds that ship the SCTP module and have not yet incorporated the patch will be affected. No specific version range was published, so the safest assumption is that every kernel incorporating the stable SCTP code before the commit that introduced timer_shutdown_sync() is vulnerable. The fix appears in the kernel repository at commits referenced in the advisory links.

Risk and Exploitability

The CVSS score is 7.8, indicating high severity, but the EPSS metric remains low at <1%. The vulnerability permits a use‑after‑free that could allow local privilege escalation if an attacker can trigger the race condition. Based on the description, it is inferred that an attacker might attempt to trigger the race by sending crafted SCTP packets, but the attack vector is not explicitly confirmed in the advisory. No public exploit has been reported, and the vulnerability is not listed in the CISA KEV catalog. Thus the likelihood of real‑world exploitation is uncertain, but the potential impact is significant.

Generated by OpenCVE AI on August 22, 2026 at 07:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that contains the patch (see the commit history linked in the advisory).
  • If SCTP is not required, disable the SCTP kernel module using modprobe -r sctp or configure the kernel to refuse loading sctp.
  • Ensure the system is kept up to date with kernel patches and monitor vendor advisories for new updates.

Generated by OpenCVE AI on August 22, 2026 at 07:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 22 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362
CWE-416

Thu, 20 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-364
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 17 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362
CWE-416

Mon, 17 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Mon, 17 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 15 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Sat, 15 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: sctp: fix addr_wq_timer race in sctp_free_addr_wq() sctp_free_addr_wq() previously removed addr_wq_timer using timer_delete() while holding addr_wq_lock. However, timer_delete() does not guarantee that a currently running timer handler has completed. This allows a race with sctp_addr_wq_timeout_handler(), where the handler may still run after addr_waitq has been freed, acquire addr_wq_lock, and access freed memory, leading to a use-after-free. Fix this by calling timer_shutdown_sync() before taking addr_wq_lock. This guarantees that any in-flight timer handler has finished and prevents the timer from being re-armed during teardown, making subsequent cleanup safe.
Title sctp: fix addr_wq_timer race in sctp_free_addr_wq()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-17T05:43:34.215Z

Reserved: 2026-08-09T03:40:39.923Z

Link: CVE-2026-72383

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T06:22:11.813

Modified: 2026-08-17T06:18:42.793

Link: CVE-2026-72383

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-15T00:00:00Z

Links: CVE-2026-72383 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T07:45:17Z

Weaknesses
  • CWE-364

    Signal Handler Race Condition