Junglewise Threat Intelligence

CVE-2026-74586: Linux kernel SCTP use-after-free in transport handling

CVE-2026-74586 · Severity: critical · CVSS 9.8 · Published 2026-08-22

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's SCTP (Stream Control Transmission Protocol) subsystem, used for reliable messaging in telecommunications and VoIP systems, contains a use-after-free vulnerability. An authenticated remote peer can craft a malicious ASCONF chunk that adds and removes a transport in the same message, causing the kernel to later read from a freed memory location. This can lead to system crashes or potentially arbitrary code execution on affected servers.

Technical details

A use-after-free vulnerability exists in the Linux kernel's SCTP implementation in the ASCONF parameter processing code. The vulnerability occurs when an authenticated SCTP peer sends an ASCONF chunk that adds a new transport and then removes it via a wildcard DEL-IP parameter within the same chunk. The removal function (sctp_assoc_del_nonprimary_peers) frees the newly added transport but does not clear the asoc->new_transport pointer. Later, sctp_sf_do_asconf() uses this stale pointer to create a HEARTBEAT message, which references freed memory. When the ASCONF_ACK is processed, sctp_outq_select_transport() attempts to read the freed transport's state field, triggering a use-after-free. The fix is to clear new_transport when its peer is removed, preventing subsequent access to the freed memory.

Affected products

  • Linux Linux kernel unfixed versions prior to patch

Timeline

  • 2026-08-22: disclosed
  • patched: Patch released clearing new_transport on peer removal

Related threats