« Volver al listado

CVE-2026-46227

Estado: ModificadaAlta (7.8)—

In the Linux kernel, the following vulnerability has been resolved:

sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL

The SCTP_SENDALL path in sctp_sendmsg() iterates ep->asocs with list_for_each_entry_safe(), which caches the next entry in @tmp before the loop body runs. The body calls sctp_sendmsg_to_asoc(), which may drop the socket lock inside sctp_wait_for_sndbuf().

While the lock is dropped, another thread can SCTP_SOCKOPT_PEELOFF the association cached in @tmp, migrating it to a new endpoint via sctp_sock_migrate() (list_del_init() + list_add_tail() to newep->asocs), and optionally close the new socket which frees the association via kfree_rcu().

Leer descripción completaMostrar menos

The cached @tmp can also be freed by a network ABORT for that association, processed in softirq while the lock is dropped.

sctp_wait_for_sndbuf() revalidates @asoc (the current entry) on re-lock via the "sk != asoc->base.sk" and "asoc->base.dead" checks, but nothing revalidates @tmp. After a successful return, the iterator advances to the stale @tmp, yielding either a use-after-free (if the peeled socket was closed) or a list-walk onto the new endpoint's list head (type confusion of &newep->asocs as a struct sctp_association *).

Both are reachable from CapEff=0; the type-confusion path gives controlled indirect call via the outqueue.sched->init_sid pointer.

Fix by re-deriving @tmp from @asoc after sctp_sendmsg_to_asoc() returns. @asoc is known to still be on ep->asocs at that point: the only callers that list_del an association from ep->asocs are sctp_association_free() (which sets asoc->base.dead) and sctp_assoc_migrate() (which changes asoc->base.sk), and sctp_wait_for_sndbuf() checks both under the lock before any successful return; a tripped check propagates as err < 0 and the loop bails before the re-derive.

The SCTP_ABORT path in sctp_sendmsg_check_sflags() returns 0 and the loop hits 'continue' before sctp_sendmsg_to_asoc() is ever called, so the @tmp cached by list_for_each_entry_safe() still covers the lock-held free that ba59fb027307 ("sctp: walk the list of asoc safely") was added for.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad local (AV:L, PR:L) que permite escalada de privilegios mediante uso después de liberación (CWE-416) en SCTP del kernel Linux, permitiendo ejecución de código arbitrario con privilegios elevados sin interacción del usuario (UI:N).

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-46227",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      },
      {
        "type": "Secondary",
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4910280503f3af2857d5aa77e35b22d93a8960a8",
              "lessThan": "f3a3f0b406b4b7eb3cea35a23fa2bf170848b104",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4910280503f3af2857d5aa77e35b22d93a8960a8",
              "lessThan": "0dbc8cde64280fc37cdd678cced34eaf96cfb197",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4910280503f3af2857d5aa77e35b22d93a8960a8",
              "lessThan": "0c7b55974f97b78d1109025eadf084e74cbf330f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4910280503f3af2857d5aa77e35b22d93a8960a8",
              "lessThan": "1bfb06ecb00f7fdf35dba8e8f2877346cbe5e078",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4910280503f3af2857d5aa77e35b22d93a8960a8",
              "lessThan": "6187a172d6ed57d6b2c327836e4407c6456e639d",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4910280503f3af2857d5aa77e35b22d93a8960a8",
              "lessThan": "c9dadb31f36045a8cb65df4bd75e7237ef21a4b5",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4910280503f3af2857d5aa77e35b22d93a8960a8",
              "lessThan": "bf0f40d8107e2ce827521968dc6926f3e13728ae",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4910280503f3af2857d5aa77e35b22d93a8960a8",
              "lessThan": "abb5f36771cc4c05899b34000829a787572a8817",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "net/sctp/socket.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.17"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "4.17",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.258",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.209",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.175",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.140",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.90",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.32",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.0.9",
              "versionType": "semver",
              "lessThanOrEqual": "7.0.*"
            },
            {
              "status": "unaffected",
              "version": "7.1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/sctp/socket.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    },
    {
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
      "affectedData": [
        {
          "cpes": [
            "cpe:/o:redhat:enterprise_linux:10.2"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Enterprise Linux 10",
          "versions": [
            {
              "status": "unaffected",
              "version": "0:6.12.0-211.32.1.el10_2",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "kernel",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/o:redhat:enterprise_linux_eus:10.0"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Enterprise Linux 10.0 Extended Update Support",
          "versions": [
            {
              "status": "unaffected",
              "version": "0:6.12.0-55.82.1.el10_0",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "kernel",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:enterprise_linux:8::nfv"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Enterprise Linux 8",
          "versions": [
            {
              "status": "unaffected",
              "version": "0:4.18.0-553.140.1.rt7.481.el8_10",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "kernel-rt",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/o:redhat:enterprise_linux:8"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Enterprise Linux 8",
          "versions": [
            {
              "status": "unaffected",
              "version": "0:4.18.0-553.140.1.el8_10",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "kernel",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/o:redhat:rhel_aus:8.4"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
          "versions": [
            {
              "status": "unaffected",
              "version": "0:4.18.0-305.194.1.el8_4",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "kernel",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/o:redhat:rhel_eus_long_life:8.4"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
          "versions": [
            {
              "status": "unaffected",
              "version": "0:4.18.0-305.194.1.el8_4",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "kernel",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/o:redhat:rhel_aus:8.6"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
          "versions": [
            {
              "status": "unaffected",
              "version": "0:4.18.0-372.198.1.el8_6",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "kernel",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/o:redhat:rhel_eus_long_life:8.6"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
          "versions": [
            {
              "status": "unaffected",
              "version": "0:4.18.0-372.198.1.el8_6",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "kernel",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/o:redhat:rhel_tus:8.8"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
          "versions": [
            {
              "status": "unaffected",
              "version": "0:4.18.0-477.147.1.el8_8",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "kernel",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/o:redhat:rhel_e4s:8.8"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
          "versions": [
            {
              "status": "unaffected",
              "version": "0:4.18.0-477.147.1.el8_8",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "kernel",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:enterprise_linux:9",
            "cpe:/o:redhat:enterprise_linux:9"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Enterprise Linux 9",
          "versions": [
            {
              "status": "unaffected",
              "version": "0:5.14.0-687.22.1.el9_8",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "kernel",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:rhel_e4s:9.2"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
          "versions": [
            {
              "status": "unaffected",
              "version": "0:5.14.0-284.176.1.el9_2",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "kernel",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:rhel_e4s:9.2::nfv"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
          "versions": [
            {
              "status": "unaffected",
              "version": "0:5.14.0-284.176.1.rt14.461.el9_2",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "kernel-rt",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:rhel_e4s:9.4"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
          "versions": [
            {
              "status": "unaffected",
              "version": "0:5.14.0-427.132.1.el9_4",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "kernel",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:rhel_eus:9.6"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Enterprise Linux 9.6 Extended Update Support",
          "versions": [
            {
              "status": "unaffected",
              "version": "0:5.14.0-570.125.1.el9_6",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "kernel",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/o:redhat:enterprise_linux:6"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Enterprise Linux 6",
          "packageName": "kernel",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "unaffected"
        },
        {
          "cpes": [
            "cpe:/o:redhat:enterprise_linux:7"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Enterprise Linux 7",
          "packageName": "kernel",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-05-28T10:16:38.317",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/0c7b55974f97b78d1109025eadf084e74cbf330f",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/0dbc8cde64280fc37cdd678cced34eaf96cfb197",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/1bfb06ecb00f7fdf35dba8e8f2877346cbe5e078",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/6187a172d6ed57d6b2c327836e4407c6456e639d",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/abb5f36771cc4c05899b34000829a787572a8817",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/bf0f40d8107e2ce827521968dc6926f3e13728ae",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c9dadb31f36045a8cb65df4bd75e7237ef21a4b5",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f3a3f0b406b4b7eb3cea35a23fa2bf170848b104",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:26462",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:26515",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:26535",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:26563",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:27731",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:27735",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:33899",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:34094",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:36018",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:36348",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:36349",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:36956",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:59142",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:59143",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:59145",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:59146",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:59147",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:59148",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:59149",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
    },
    {
      "url": "https://access.redhat.com/security/cve/CVE-2026-46227",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2482564",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
    },
    {
      "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46227.json",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-416"
        }
      ]
    },
    {
      "type": "Secondary",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
      "description": [
        {
          "lang": "en",
          "value": "CWE-367"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL\n\nThe SCTP_SENDALL path in sctp_sendmsg() iterates ep->asocs with\nlist_for_each_entry_safe(), which caches the next entry in @tmp before\nthe loop body runs.  The body calls sctp_sendmsg_to_asoc(), which may\ndrop the socket lock inside sctp_wait_for_sndbuf().\n\nWhile the lock is dropped, another thread can SCTP_SOCKOPT_PEELOFF the\nassociation cached in @tmp, migrating it to a new endpoint via\nsctp_sock_migrate() (list_del_init() + list_add_tail() to\nnewep->asocs), and optionally close the new socket which frees the\nassociation via kfree_rcu().  The cached @tmp can also be freed by a\nnetwork ABORT for that association, processed in softirq while the\nlock is dropped.\n\nsctp_wait_for_sndbuf() revalidates @asoc (the current entry) on re-lock\nvia the \"sk != asoc->base.sk\" and \"asoc->base.dead\" checks, but nothing\nrevalidates @tmp.  After a successful return, the iterator advances to\nthe stale @tmp, yielding either a use-after-free (if the peeled socket\nwas closed) or a list-walk onto the new endpoint's list head (type\nconfusion of &newep->asocs as a struct sctp_association *).\n\nBoth are reachable from CapEff=0; the type-confusion path gives\ncontrolled indirect call via the outqueue.sched->init_sid pointer.\n\nFix by re-deriving @tmp from @asoc after sctp_sendmsg_to_asoc()\nreturns.  @asoc is known to still be on ep->asocs at that point: the\nonly callers that list_del an association from ep->asocs are\nsctp_association_free() (which sets asoc->base.dead) and\nsctp_assoc_migrate() (which changes asoc->base.sk), and\nsctp_wait_for_sndbuf() checks both under the lock before any\nsuccessful return; a tripped check propagates as err < 0 and the loop\nbails before the re-derive.\n\nThe SCTP_ABORT path in sctp_sendmsg_check_sflags() returns 0 and the\nloop hits 'continue' before sctp_sendmsg_to_asoc() is ever called, so\nthe @tmp cached by list_for_each_entry_safe() still covers the\nlock-held free that ba59fb027307 (\"sctp: walk the list of asoc\nsafely\") was added for."
    }
  ],
  "lastModified": "2026-08-25T13:19:15.520",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CF9EFBB4-E004-479B-A237-DECC87FD4D0E",
              "versionEndExcluding": "5.10.258",
              "versionStartIncluding": "4.17"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "919C10A9-7951-4A74-BADD-C135A0A8D8B4",
              "versionEndExcluding": "5.15.209",
              "versionStartIncluding": "5.11"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "92385813-D91D-480D-83A1-F423D2CBB2BA",
              "versionEndExcluding": "6.1.175",
              "versionStartIncluding": "5.16"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A1A92866-F406-43B5-B2D1-CFC274753E9D",
              "versionEndExcluding": "6.6.140",
              "versionStartIncluding": "6.2"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3BAAA2BE-6EEC-45D5-AD66-50F63CA20483",
              "versionEndExcluding": "6.12.90",
              "versionStartIncluding": "6.7"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CB9F1FA8-6D5E-42B1-9877-57BACFE5C886",
              "versionEndExcluding": "6.18.32",
              "versionStartIncluding": "6.13"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "33ACA10B-B260-46EA-BD50-70EBE5097672",
              "versionEndExcluding": "7.0.9",
              "versionStartIncluding": "6.19"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B1EF7059-E670-45F4-B422-54C40FA86390"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0D38F0BF-A728-4133-A358-D44A2F7EE6D6"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EC732D08-5F7B-46D9-B154-E60C7F4F0A97"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}