Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-68161

sctp: close UDP tunnel sockets during netns teardown
Back to all
CVE

CVE-2026-68161

sctp: close UDP tunnel sockets during netns teardown

In the Linux kernel, the following vulnerability has been resolved:

sctp: close UDP tunnel sockets during netns teardown

procsctpdoudpport() starts per-net SCTP UDP tunneling sockets when

net.sctp.udp_port is set, and stops/restarts them when the sysctl value

changes. The netns exit path does not stop these sockets, so a namespace

can be torn down while its SCTP UDP tunnel sockets are still installed.

Close the UDP tunnel sockets from sctpctrlsockexit() after unregistering

the per-net sysctl table. This prevents new sysctl writes from racing in

while the sockets are being released, and closes the sockets before the

control socket is destroyed.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
9.8
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
-

Related Resources

No items found.

References

https://git.kernel.org/stable/c/37ff9794be48d0caa37687e04d09675f9c849121, https://git.kernel.org/stable/c/3bf0e349cbb4f975f35eb22753acc346b89c66a0, https://git.kernel.org/stable/c/8ff78591d309c50a4fdab683b68dd8d512a270dd, https://git.kernel.org/stable/c/c6eb2d615210b80339548ab07c0230edaab9a6c7, https://git.kernel.org/stable/c/ffb2bd7ade36ec4da32c46a6eddbf4515316d08c, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68161.json, https://nvd.nist.gov/vuln/detail/CVE-2026-68161, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Severity

9.8

CVSS Score
0
10

Basic Information

Base CVSS
9.8
EPSS Probability
0.00626%
EPSS Percentile
0.47405%
Introduced Version
046c052b475e7119b6a30e3483e2888fc606a2f8,5.11.0,6.7.0,6.13.0,6.19.0,0
Fix Available
ffb2bd7ade36ec4da32c46a6eddbf4515316d08c,6.6.151,6.12.101,6.18.42,7.1.6,6.12.101-1~deb12u1,6.12.101-1

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading