Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-74588

sctp: keep chunk->transport in step with the list it is queued on
Back to all
CVE

CVE-2026-74588

sctp: keep chunk->transport in step with the list it is queued on

In the Linux kernel, the following vulnerability has been resolved:

sctp: keep chunk->transport in step with the list it is queued on

_sctpoutqflushrtx() moves a gap-acked chunk onto another transport's

transmitted list without updating chunk->transport:

if (chunk->tsngapacked) {

listmovetail(&chunk->transmitted_list,

       &transport->transmitted);

continue;

}

The chunk then sits on a live transport's list while chunk->transport still

names a different one.  If that transport is removed - sctpassocrm_peer()

from an ASCONF Delete-IP - sctptransportfree() RCU-frees it and the chunk

is left with a dangling pointer.  sctpassocrm_peer() scrubs

peer->transmitted and asoc->outqueue.outchunklist, but the chunk is on

neither.

The pointer is not followed while tsngapacked is set.  A SACK that

reneges on the TSN clears the flag, and the next SACK reaches

tchunk->transport->flightsize -= sctpdata_size(tchunk);

inside the freed transport.  KASAN reports a slab-use-after-free read in

sctpchecktransmitted(), freed from sctpassocrm_peer().  Both the

removal and the SACKs come from the association peer.

Set chunk->transport at the move.  The ordinary resend path needs nothing:

it reaches its listmovetail() only after sctppacketappend_chunk()

returned SCTPXMITOK, and _sctppacketappendchunk() has rebound the

chunk by then.

Discovered by XBOW, triaged by Baul Lee baul.lee@xbow.com

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
9.8
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
-

Related Resources

No items found.

References

https://git.kernel.org/stable/c/1adf929121e13e0b19200bb9fef715b918d483fe, https://git.kernel.org/stable/c/2b3b5eec8b2c30ee237e3c31a6a38de9c39d804d, https://git.kernel.org/stable/c/5ccf35ef0ed6059cdf8b1f4606a6584d5b67166b, https://git.kernel.org/stable/c/6575fb17230814b48b471727c8410c0aadff9274, https://git.kernel.org/stable/c/6b9e2ea2057113f3393990ba646d2d97c719a80d, https://git.kernel.org/stable/c/874a7c2b5e184f06134fdfde27e9ce9271bafe58, https://git.kernel.org/stable/c/9f2cf069a9a72a2d6b97ca8b4c70e714aac99749, https://git.kernel.org/stable/c/e2e7c1de0e226ca1b7fea2de57a6c9bca408709b, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74588.json, https://nvd.nist.gov/vuln/detail/CVE-2026-74588, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Severity

9.8

CVSS Score
0
10

Basic Information

Base CVSS
9.8
EPSS Probability
0.00734%
EPSS Percentile
0.5255%
Introduced Version
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2,2.6.12,5.11.0,5.16.0,6.2.0,6.7.0,6.13.0,6.19.0,0
Fix Available
9f2cf069a9a72a2d6b97ca8b4c70e714aac99749,5.10.265,5.15.216,6.1.183,6.6.152,6.12.104,6.18.45,7.1.9,6.1.187-1,6.12.107-1~deb12u1,6.12.105-1,0:6.12.0-206.104.3.3.el10uek,0:5.15.0-324.217.5.2.el8uek,0:5.15.0-324.217.5.2.el9uek,0:6.12.0-206.104.3.3.el9uek,0:5.10.265-265.1078.amzn2,0:1.0-0.amzn2,0:5.15.220-153.252.amzn2,1:6.1.186-228.374.amzn2023,1:1.0-0.amzn2023,1:6.18.48-107.148.amzn2023

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading