Junglewise Threat Intelligence

CVE-2026-74587: Linux kernel SCTP use-after-free in cached ASCONF chunk

CVE-2026-74587 · Severity: critical · CVSS 9.8 · Published 2026-08-22

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's SCTP protocol implementation contains a use-after-free vulnerability in its handling of cached ASCONF (Add-IP) configuration chunks. An attacker on the network can craft specific protocol messages to trigger a crash or potentially execute code on systems using affected kernel versions, compromising system availability and security.

Technical details

The vulnerability exists in the SCTP implementation's caching of ASCONF chunks via the addip_last_asconf pointer. During peer restart handling, sctp_asconf_queue_teardown() releases the cached chunk without clearing the pointer, leaving it dangling. A delayed authenticated ASCONF-ACK can then reach sctp_sf_do_asconf_ack(), which dereferences the stale chunk and causes a use-after-free. Additionally, clearing the pointer exposes a race condition with T4 timer expiry: timer_delete() does not wait for callbacks already running on another CPU, allowing sctp_sf_t4_timer_expire() to dereference a NULL pointer after purge. The fix clears addip_last_asconf after releasing the chunk and adds a NULL check in the T4 timer handler. Attack requires network reachability to the SCTP endpoint and the ability to send crafted SCTP packets.

Affected products

  • Linux Linux Kernel multiple versions through 6.18 and earlier (see stable tree branches)

Timeline

  • 2026-08-22: disclosed: CVE-2026-74587 published

References

Related threats