Executive brief
The Linux kernel's SCTP (Stream Control Transmission Protocol) implementation contains memory leaks in INIT packet processing. Attackers can send specially crafted network packets to trigger memory leaks in the kernel network stack, causing gradual memory exhaustion and potential denial of service through system resource depletion.
Technical details
This is a memory leak vulnerability in the SCTP protocol handler within the Linux kernel. The sctp_verify_init() function allocates an err_chunk structure to report unrecognized parameters in INIT packets, but this chunk is not freed in three code paths: (1) sctp_sf_do_5_1B_init() when security_sctp_assoc_request() fails, (2) sctp_sf_do_unexpected_init() on the same security check failure, and (3) sctp_sf_do_unexpected_init() on the success path after copying parameters to INIT-ACK. An attacker can send specially crafted SCTP INIT packets with unrecognized parameters to trigger these leak paths repeatedly, causing kernel memory to be gradually exhausted. The fix adds sctp_chunk_free() calls before returning in the affected code paths. No special authentication or local access is required; the vulnerability is reachable from the network.
Affected products
- Linux Linux kernel multiple versions through at least 6.9.y; patched in upstream commit 9f58a0a4d6c2ed5d341bba64f058f15d1b0c36f2
Timeline
- 2026-08-15: disclosed: CVE-2026-72413 published
- 2026-09-21: patched: Fix committed to stable Linux kernel branches