๐Ÿ” CVE Alert

CVE-2026-64564

UNKNOWN 0.0

sctp: don't free the ASCONF's own transport in DEL-IP processing

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: sctp: don't free the ASCONF's own transport in DEL-IP processing sctp_process_asconf() caches the transport the ASCONF chunk is processed against in asconf->transport (== chunk->transport, set once in sctp_rcv()). For an ASCONF located through its Address Parameter by __sctp_rcv_asconf_lookup(), that cached transport corresponds to the Address Parameter, which need not be the packet's source address. sctp_process_asconf_param() rejects a DEL-IP for the packet source address (ADDIP D8, SCTP_ERROR_DEL_SRC_IP), but nothing protects asconf->transport. A single ASCONF can therefore carry, in order: [Address Parameter L] [DEL-IP L] [DEL-IP 0.0.0.0] where L differs from the source. The DEL-IP for L passes the D8 check and calls sctp_assoc_rm_peer() on the transport that asconf->transport still points at, freeing it (RCU-deferred). The following wildcard DEL-IP then reuses the now-dangling asconf->transport in sctp_assoc_set_primary() and sctp_assoc_del_nonprimary_peers(): set_primary() dereferences the freed transport (->ipaddr, ->state) and plants the dangling pointer into asoc->peer.primary_path / active_path, and del_nonprimary_peers(), keeping only the pointer that is no longer on the list, removes every real transport, leaving the association with a transport_count of 0 and primary_path/active_path pointing at freed memory. Reject a DEL-IP that targets the transport the ASCONF is being processed against, mirroring the existing source-address guard, so the wildcard branch can never reuse a freed transport.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Aug 4, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
42e30bf3463cd37d73839376662cb79b4d5c416c < fedeb4468987bcaff85fe3061de5ae052d414740 42e30bf3463cd37d73839376662cb79b4d5c416c < 74e8f3e7114f0e26d1b2c4c048044db9fcc27603 42e30bf3463cd37d73839376662cb79b4d5c416c < 85aca407c560aba81b5ce9d3d6cf94c74077d19b 42e30bf3463cd37d73839376662cb79b4d5c416c < d136b29bf91dd8e3161281b87de597b7311d9462 42e30bf3463cd37d73839376662cb79b4d5c416c < 9b2854f86f0b56e9027d68e7a3fc909d1a9b566f
Linux / Linux
2.6.25

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/fedeb4468987bcaff85fe3061de5ae052d414740 git.kernel.org: https://git.kernel.org/stable/c/74e8f3e7114f0e26d1b2c4c048044db9fcc27603 git.kernel.org: https://git.kernel.org/stable/c/85aca407c560aba81b5ce9d3d6cf94c74077d19b git.kernel.org: https://git.kernel.org/stable/c/d136b29bf91dd8e3161281b87de597b7311d9462 git.kernel.org: https://git.kernel.org/stable/c/9b2854f86f0b56e9027d68e7a3fc909d1a9b566f