Junglewise Threat Intelligence

CVE-2026-74688: Linux kernel SCTP use-after-free in control chunk transport

CVE-2026-74688 · Severity: critical · CVSS 9.8 · Published 2026-08-22

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's SCTP networking protocol implementation has a use-after-free vulnerability in how it manages transport connections for heartbeat acknowledgment messages. When a peer connection is removed while a queued message references it, the kernel may later attempt to access the freed memory, causing a system crash or potential code execution. This affects systems using SCTP for real-time or IP telephony communications.

Technical details

The vulnerability is a use-after-free in the SCTP subsystem's control chunk handling. The root cause: sctp_make_heartbeat_ack() caches a destination transport pointer in chunk->transport without incrementing a reference count. When src_out_of_asoc_ok is enabled, the HEARTBEAT ACK may remain queued on control_chunk_list instead of being sent immediately. If the peer transport is removed via sctp_assoc_rm_peer(), the function clears cached transport pointers in out_chunk_list but fails to clear them in control_chunk_list. This leaves a dangling pointer. When an ASCONF_ACK later clears suppression and the queued chunk is transmitted, SCTP dereferences the stale transport pointer. The fix adds code to iterate control_chunk_list and clear chunk->transport pointers matching the removed peer. No special privileges or network access preconditions beyond SCTP connectivity are known to be required.

Affected products

  • Linux Linux kernel multiple versions; detailed version range not specified in advisory

Timeline

  • 2026-08-05: other: Patch authored by Xin Long
  • 2026-08-19: patched: Patch merged in stable kernel tree
  • 2026-08-22: disclosed

References

Related threats