Executive brief
A vulnerability in the Linux kernel's networking component could cause network performance issues or connection drops when using specific data transfer protocols (SCTP over UDP). This issue occurs because the system may incorrectly handle internal counters when processing network traffic across multiple processor cores. For a business, this could manifest as intermittent service disruptions or significantly degraded network throughput for applications relying on these protocols.
Technical details
A race condition exists in the Linux kernel's SCTP implementation when using UDP encapsulation. The functions udp_tunnel_xmit_skb() and udp_tunnel6_xmit_skb() expect to run with bottom halves (BH) disabled to ensure that recursion increment/decrement operations (dev_xmit_recursion_inc/dec) remain balanced on the same CPU. Without local_bh_disable(), a context switch between CPUs can occur, breaking the pairing and leading to incorrect recursion level detection. This results in legitimate packets being dropped in ip(6)_tunnel_xmit() or __dev_queue_xmit(). The issue affects both IPv4 and IPv6 paths and has been resolved by wrapping the transmission calls with local_bh_disable() and local_bh_enable().
Affected products
- Linux Linux Kernel 5.11 to 7.0.10
Timeline
- 2026-04-12: other: Patch authored
- 2026-06-24: disclosed: CVE published