Junglewise Threat Intelligence

CVE-2026-72383: Linux kernel SCTP use-after-free in addr_wq_timer

CVE-2026-72383 · Severity: high · CVSS 7.8 · Published 2026-08-15

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's SCTP (Stream Control Transmission Protocol) networking module contains a race condition in timer cleanup code that can lead to use-after-free. An attacker with local network access could trigger this condition during network namespace teardown to access freed memory, potentially causing a denial of service or information disclosure on systems using SCTP.

Technical details

This is a use-after-free vulnerability in the SCTP protocol implementation (net/sctp/protocol.c). The vulnerable code path occurs in sctp_free_addr_wq(), which previously called timer_delete() while holding a spinlock. The timer_delete() function does not guarantee that a running timer handler (sctp_addr_wq_timeout_handler) has completed execution. A race condition allows the handler to run after the address wait queue has been freed, acquire the lock, and dereference freed memory. The fix replaces timer_delete() with timer_shutdown_sync() called before acquiring the lock, ensuring the handler completes and prevents re-arming. The vulnerability was introduced in commit 4db67e808640 and affects all Linux kernel versions with per-namespace SCTP address lists.

Affected products

  • Linux Linux Kernel 2.6.11 through 6.x (all versions with SCTP per-namespace support from commit 4db67e808640 onwards)

Timeline

  • 2026-08-15: disclosed
  • 2026-06-30: patched: Fix merged in mainline; backports to stable branches from 2026-07-24 onwards

References

Related threats