← All Advisories

Linux Kernel SCTP Authenticated ASCONF DEL-IP Removes a Transport While a Backlogged Chunk Still Holds a Pointer to It, Enabling Use-After-Free on the Next SACK

Last refreshed2026-09-28

Status: NEW  |  Advisory ID: CVE-2026-89478

Key Details

CVECVE-2026-89478
CVSS Score / Version9.8 (Critical) / CVSS v3.1
Updated2026-09-14
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.

What to Know

In the Linux kernel, the following vulnerability has been resolved:

sctp: drop a chunk if its transport was removed

sctp_rcv() resolves the transport once per packet and leaves it in

chunk->transport. The lookup reference, or the one sctp_add_backlog() takes

if the socket is owned by userspace, keeps it around until the chunk has

been processed.

An authenticated ASCONF DEL-IP can remove it in the meantime.

sctp_assoc_rm_peer() takes the transport out of the association and calls

sctp_transport_free(), which tags it dead and drops the reference the

association held. There is a window on both paths: the packet can sit on

the socket backlog, and on the direct path the lookup completes before

bh_lock_sock().

The DATA chunk in that packet puts the removed transport back into

asoc->peer.last_data_from. Once the packet is done that reference goes

away and the transport is freed by RCU, so the next delayed SACK carries

the pointer into the SACK chunk and sctp_outq_select_transport() reads the

freed transport's state.

Drop the chunk in sctp_inq_push(), next to the existing rcvr->dead check.

Both paths reach it with the association's socket lock held. The peer

retransmits it. (NVD)

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-89478
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-89478