Executive brief
The Linux kernel's SCTP (Stream Control Transmission Protocol) subsystem, used for reliable messaging in telecommunications and VoIP systems, contains a use-after-free vulnerability. An authenticated remote peer can craft a malicious ASCONF chunk that adds and removes a transport in the same message, causing the kernel to later read from a freed memory location. This can lead to system crashes or potentially arbitrary code execution on affected servers.
Technical details
A use-after-free vulnerability exists in the Linux kernel's SCTP implementation in the ASCONF parameter processing code. The vulnerability occurs when an authenticated SCTP peer sends an ASCONF chunk that adds a new transport and then removes it via a wildcard DEL-IP parameter within the same chunk. The removal function (sctp_assoc_del_nonprimary_peers) frees the newly added transport but does not clear the asoc->new_transport pointer. Later, sctp_sf_do_asconf() uses this stale pointer to create a HEARTBEAT message, which references freed memory. When the ASCONF_ACK is processed, sctp_outq_select_transport() attempts to read the freed transport's state field, triggering a use-after-free. The fix is to clear new_transport when its peer is removed, preventing subsequent access to the freed memory.
Affected products
- Linux Linux kernel unfixed versions prior to patch
Timeline
- 2026-08-22: disclosed
- patched: Patch released clearing new_transport on peer removal