Description
In the Linux kernel, the following vulnerability has been resolved:

sctp: stop processing a packet once its association is deleted

sctp_endpoint_bh_rcv() looks the association up only when chunk->asoc is
NULL, and caches the result in chunk->asoc and chunk->transport without
taking a reference.

A packet that matches no association is handed to the endpoint, so a peer
can bundle COOKIE ECHO, SHUTDOWN and SHUTDOWN ACK in one packet. The
COOKIE ECHO creates the association, the SHUTDOWN chunk caches it, and
with the outqueue empty the SHUTDOWN ACK reaches sctp_sf_do_9_2_final(),
so the association and its transports are freed.

The endpoint loop has no counterpart to the asoc->base.dead check in
sctp_assoc_bh_rcv(). The next chunk writes to last_time_heard in the freed
transport and is then passed to sctp_do_sm() with the freed association.
The transport is freed through RCU, so this needs the packet to come off
the socket backlog, where the loop runs in task context.

The endpoint loop cannot do the same check: it holds no reference on the
association, so reading asoc->base.dead would itself be a use-after-free.
Mark the packet for discard in the command interpreter, just before it
deletes the association. That is also before sctp_inq_free() releases the
chunk on the association receive path.

sctp_sf_do_5_2_4_dupcook() issues SCTP_CMD_DELETE_TCB for the temporary
association, while the one the packet belongs to stays alive. A restarting
peer can bundle DATA behind its COOKIE ECHO, so compare against
chunk->asoc and leave that case alone.
Published: 2026-09-11
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Use‑after‑free leading to kernel crash or code execution
Action: Immediate Patch
AI Analysis

Impact

The Linux kernel SCTP stack has a use‑after‑free bug that can be triggered by sending a, SHUTDOWN, or SHUTDOWN ACK chunk. The bug occurs when the endpoint processes a packet after its association has been freed, writing to freed memory and potentially corrupting kernel state. In the worst case an attacker can gain kernel code execution or cause a system crash by manipulating the freed data.

Affected Systems

Affected systems are Linux kernel installations that include the SCTP protocol stack, whether built‑in or via the sctp module. Systems running any Linux kernel version that contains the SCTP implementation prior to the fix are susceptible.

Risk and Exploitability

The CVSS score of 9.8 classifies the vulnerability as Critical. Its EPSS score is listed as < 1 %, indicating a low probability of exploitation, and it is not present in the CISA KEV catalog. The likely attack vector is remote: an attacker can send the malicious SCTP packets over the network to the target host. Successful exploitation would result in denial of service through a kernel crash and, if the attacker can influence the freed memory contents, arbitrary code execution at kernel level. The vulnerability requires that the attacker bundles specific SCTP chunks in a single packet, connection.

Generated by OpenCVE AI on September 15, 2026 at 22:47 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel patch that implements the SCTP use‑after‑free fix; follow the immediate update is not possible and SCTP functionality is not required, disable the SCTP protocol by unloading the sctp module or blocking port 5000 in the firewall to prevent malicious packets from reaching the kernel.
  • Continuously monitor kernel logs for SCTP‑related faults or unexpected crashes and apply the latest kernel update as soon as it becomes available.
  • Consult Linux kernel security advisories regularly to receive timely updates for the SCTP stack.

Generated by OpenCVE AI on September 15, 2026 at 22:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-825
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Important


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: sctp: stop processing a packet once its association is deleted sctp_endpoint_bh_rcv() looks the association up only when chunk->asoc is NULL, and caches the result in chunk->asoc and chunk->transport without taking a reference. A packet that matches no association is handed to the endpoint, so a peer can bundle COOKIE ECHO, SHUTDOWN and SHUTDOWN ACK in one packet. The COOKIE ECHO creates the association, the SHUTDOWN chunk caches it, and with the outqueue empty the SHUTDOWN ACK reaches sctp_sf_do_9_2_final(), so the association and its transports are freed. The endpoint loop has no counterpart to the asoc->base.dead check in sctp_assoc_bh_rcv(). The next chunk writes to last_time_heard in the freed transport and is then passed to sctp_do_sm() with the freed association. The transport is freed through RCU, so this needs the packet to come off the socket backlog, where the loop runs in task context. The endpoint loop cannot do the same check: it holds no reference on the association, so reading asoc->base.dead would itself be a use-after-free. Mark the packet for discard in the command interpreter, just before it deletes the association. That is also before sctp_inq_free() releases the chunk on the association receive path. sctp_sf_do_5_2_4_dupcook() issues SCTP_CMD_DELETE_TCB for the temporary association, while the one the packet belongs to stays alive. A restarting peer can bundle DATA behind its COOKIE ECHO, so compare against chunk->asoc and leave that case alone.
Title sctp: stop processing a packet once its association is deleted
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T12:00:16.005Z

Reserved: 2026-09-11T19:38:34.711Z

Link: CVE-2026-89479

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:29.337

Modified: 2026-09-14T13:19:04.457

Link: CVE-2026-89479

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-11T19:43:35Z

Links: CVE-2026-89479 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T23:00:16Z

Weaknesses
  • CWE-825

    Expired Pointer Dereference