Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-89479

sctp: stop processing a packet once its association is deleted
Back to all
CVE

CVE-2026-89479

sctp: stop processing a packet once its association is deleted

In the Linux kernel, the following vulnerability has been resolved:

sctp: stop processing a packet once its association is deleted

sctpendpointbh_rcv() looks the association up only when chunk->asoc is

NULL, and caches the result in chunk->asoc and chunk->transport without

taking a reference.

A packet that matches no association is handed to the endpoint, so a peer

can bundle COOKIE ECHO, SHUTDOWN and SHUTDOWN ACK in one packet. The

COOKIE ECHO creates the association, the SHUTDOWN chunk caches it, and

with the outqueue empty the SHUTDOWN ACK reaches sctpsfdo92_final(),

so the association and its transports are freed.

The endpoint loop has no counterpart to the asoc->base.dead check in

sctpassocbhrcv(). The next chunk writes to lasttime_heard in the freed

transport and is then passed to sctpdosm() with the freed association.

The transport is freed through RCU, so this needs the packet to come off

the socket backlog, where the loop runs in task context.

The endpoint loop cannot do the same check: it holds no reference on the

association, so reading asoc->base.dead would itself be a use-after-free.

Mark the packet for discard in the command interpreter, just before it

deletes the association. That is also before sctpinqfree() releases the

chunk on the association receive path.

sctpsfdo524dupcook() issues SCTPCMDDELETE_TCB for the temporary

association, while the one the packet belongs to stays alive. A restarting

peer can bundle DATA behind its COOKIE ECHO, so compare against

chunk->asoc and leave that case alone.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
9.8
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
-

Related Resources

No items found.

References

https://git.kernel.org/stable/c/09c3b193a3e8fe53e1f416e2f8e3283d2a785405, https://git.kernel.org/stable/c/47e15a8d12e366d0d261bcbc394394f44418938d, https://git.kernel.org/stable/c/5c0b2dbbdafc9eeeb11fffe1e46551fc3b55d8ee, https://git.kernel.org/stable/c/7d970353eeb98f46a3b9dc602850e4f6336a9889, https://git.kernel.org/stable/c/a713e1b3a265f180ad25a08e17be15d67a2f7149, https://git.kernel.org/stable/c/ed85fe91a61bc0e0da6b585c07102b20f4cc65a0, https://git.kernel.org/stable/c/ee3f04cf566f6041aa9a0360494fd8db5ade383a, https://git.kernel.org/stable/c/fa306a40e716c5abcd967475459ce1ebd56e5115, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89479.json, https://nvd.nist.gov/vuln/detail/CVE-2026-89479, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Severity

9.8

CVSS Score
0
10

Basic Information

Base CVSS
9.8
EPSS Probability
0.005%
EPSS Percentile
0.4088%
Introduced Version
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2,2.6.12,5.11.0,5.16.0,6.2.0,6.7.0,6.13.0,6.19.0,0
Fix Available
47e15a8d12e366d0d261bcbc394394f44418938d,5.10.270,5.15.221,6.1.188,6.6.157,6.12.109,6.18.50,7.2.4,6.12.111-1~deb12u1,6.12.111-1,0:6.12.0-207.111.5.1.el10uek,0:6.12.0-207.111.5.1.el9uek

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading