Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-74586

sctp: clear new_transport when removing a peer
Back to all
CVE

CVE-2026-74586

sctp: clear new_transport when removing a peer

In the Linux kernel, the following vulnerability has been resolved:

sctp: clear new_transport when removing a peer

sctpprocessasconf_param() stores a newly added peer transport in

asoc->new_transport. After all parameters in the ASCONF chunk have been

processed, sctpsfdo_asconf() uses this pointer to send a HEARTBEAT to the

new transport.

An authenticated ASCONF from a remote SCTP peer can add a transport and

remove it again with a wildcard DEL-IP parameter in the same chunk. The

wildcard deletion preserves the transport on which the ASCONF arrived, but

removes the newly added transport through

sctpassocdelnonprimarypeers(). The removal does not clear

asoc->new_transport, leaving it pointing to the removed transport.

sctpsfdo_asconf() then creates a HEARTBEAT whose chunk->transport points

to the removed transport without holding a transport reference. During

local address replacement, srcoutofasocok keeps this HEARTBEAT on

controlchunklist. After the transport is freed by RCU, a successful

ASCONF_ACK for the replacement address releases the queued HEARTBEAT and

sctpoutqselect_transport() reads the freed transport's state.

The issue was found during a static audit of SCTP objects. With an

authenticated peer, the reproducer triggered the same KASAN report in 2

of 2 unpatched runs on a KASAN-enabled netdev/main kernel:

  BUG: KASAN: slab-use-after-free in sctpoutqselect_transport

  Read of size 4 at addr ffff88800b9bd95c by task python3/197

  Call Trace:

   sctpoutqselect_transport+0x549/0x8b0 [sctp]

   sctpoutqflush+0x306/0x2c60 [sctp]

   sctptransportimmediate_rtx+0xaf/0x260 [sctp]

   sctpprocessasconf_ack+0xa48/0xf70 [sctp]

  Allocated by task 197:

   sctptransportnew+0x68/0x650 [sctp]

   sctpassocadd_peer+0x258/0x12a0 [sctp]

   sctpprocessasconf+0x5e9/0x1090 [sctp]

  Last potentially related work creation:

   _callrcu_common.constprop.0+0x77/0xb70

   sctpassocdelnonprimarypeers+0x7c/0xd0 [sctp]

   sctpprocessasconf+0xd9c/0x1090 [sctp]

The first invalid access was a four-byte read of transport->state at

net/sctp/outqueue.c:833. The same reproducer completed the full

authenticated ASCONF and local-address replacement sequence with this

change without a KASAN report or oops.

Clear new_transport when its peer is removed, before it can be used to

create the HEARTBEAT.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
9.8
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
-

Related Resources

No items found.

References

https://git.kernel.org/stable/c/163847552a571bd55094291f4ffcdc1de0f14a7b, https://git.kernel.org/stable/c/291accf36febce751021888de5f15090f4875b56, https://git.kernel.org/stable/c/31efa656cf6aface26e88f038c14f22ee6ca1500, https://git.kernel.org/stable/c/3b539b317cd052236fed0350364ff1268996ba46, https://git.kernel.org/stable/c/beb33f8ee1ca83acddb2a5ae80f3d22ec550b4c3, https://git.kernel.org/stable/c/c0f973bb5118dd1b146cda3fcc8af6f6057befec, https://git.kernel.org/stable/c/ca33df36aa0143a1d04f57d2086020c12e7eddb7, https://git.kernel.org/stable/c/db9d8e3b670f841755bc2018f178472dc6064d27, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74586.json, https://nvd.nist.gov/vuln/detail/CVE-2026-74586, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Severity

9.8

CVSS Score
0
10

Basic Information

Base CVSS
9.8
EPSS Probability
0.00734%
EPSS Percentile
0.52545%
Introduced Version
6af29ccc223b0feb6fc6112281c3fa3cdb1afddf,3.2.0,5.11.0,5.16.0,6.2.0,6.7.0,6.13.0,6.19.0,0
Fix Available
beb33f8ee1ca83acddb2a5ae80f3d22ec550b4c3,5.10.265,5.15.216,6.1.183,6.6.152,6.12.104,6.18.45,7.1.9,6.1.187-1,6.12.107-1~deb12u1,6.12.105-1,0:6.12.0-206.104.3.3.el10uek,0:5.15.0-324.217.5.2.el8uek,0:5.15.0-324.217.5.2.el9uek,0:6.12.0-206.104.3.3.el9uek,0:5.10.265-265.1078.amzn2,0:1.0-0.amzn2,0:5.15.220-153.252.amzn2,1:6.1.186-228.374.amzn2023,1:1.0-0.amzn2023,1:6.18.48-107.148.amzn2023

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading