CVE-2026-72021
In the Linux kernel, the following vulnerability has been resolved:
ipvs: use parsed transport offset in SCTP state lookup
set_sctp_state() reads the SCTP chunk header again in order to drive the IPVS SCTP state table. For IPv6 it computes the offset with sizeof(struct ipv6hdr), while the surrounding IPVS code uses iph.len from ip_vs_fill_iph_skb(), where ipv6_find_hdr() has already skipped extension headers and found the real transport header.
This makes the state machine read from the wrong offset for IPv6 SCTP packets that carry extension headers.
Leer descripción completaMostrar menos
For example, an INIT packet with an 8-byte destination options header can be scheduled correctly by sctp_conn_schedule(), but set_sctp_state() reads the first byte of the SCTP verification tag as a DATA chunk type. The connection then moves from NONE to ESTABLISHED instead of INIT1, gets the longer established timeout, and updates the active/inactive destination counters incorrectly. This happens even though the SCTP handshake has not completed.
Use the parsed transport offset passed down from ip_vs_set_state() for the SCTP chunk-header lookup. For IPv4 and IPv6 packets without extension headers this preserves the existing offset.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
- Puntuación base: 8.2
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.61%
- Percentil entre todas las CVEs puntuadas: 47
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access75 % - Impacto principal
T1499.004Application or System Exploitationimpact70 % - Impacto secundario
T1565.002Transmitted Data Manipulationimpact65 %
Vulnerabilidad de red (AV:N/AC:L/PR:N) en kernel de Linux que permite manipular el estado SCTP mediante paquetes IPv6 malformados, causando denegación de servicio e inconsistencia en contadores de destino activo/inactivo.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/247d055504dcc852e539b9f7f30d19f9741474bf
- https://git.kernel.org/stable/c/290e9e8389b556efc603522e28bd1543846aa336
- https://git.kernel.org/stable/c/2f75c0faa3361b28e36cc0512b3299e163e25789
- https://git.kernel.org/stable/c/9cb5ac594ca76d3a71803b23b74c835b0721e628
- https://git.kernel.org/stable/c/9f94573ab962a9e81954b755da016fa3cd2f5039
- https://git.kernel.org/stable/c/a4a2d2e483d79cc2ad3a170674cf159644acf22b
- https://git.kernel.org/stable/c/d2b8b1557ec07ea1bb5dddbceaf4dfe63d388e27
- https://git.kernel.org/stable/c/e5d0bb8871668f20de8f3c94b5ae3f372346bc6e
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-72021",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.2,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 4.2,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "2906f66a5682e5670a5eefe991843689b8d8563f",
"lessThan": "d2b8b1557ec07ea1bb5dddbceaf4dfe63d388e27",
"versionType": "git"
},
{
"status": "affected",
"version": "2906f66a5682e5670a5eefe991843689b8d8563f",
"lessThan": "9f94573ab962a9e81954b755da016fa3cd2f5039",
"versionType": "git"
},
{
"status": "affected",
"version": "2906f66a5682e5670a5eefe991843689b8d8563f",
"lessThan": "290e9e8389b556efc603522e28bd1543846aa336",
"versionType": "git"
},
{
"status": "affected",
"version": "2906f66a5682e5670a5eefe991843689b8d8563f",
"lessThan": "9cb5ac594ca76d3a71803b23b74c835b0721e628",
"versionType": "git"
},
{
"status": "affected",
"version": "2906f66a5682e5670a5eefe991843689b8d8563f",
"lessThan": "a4a2d2e483d79cc2ad3a170674cf159644acf22b",
"versionType": "git"
},
{
"status": "affected",
"version": "2906f66a5682e5670a5eefe991843689b8d8563f",
"lessThan": "247d055504dcc852e539b9f7f30d19f9741474bf",
"versionType": "git"
},
{
"status": "affected",
"version": "2906f66a5682e5670a5eefe991843689b8d8563f",
"lessThan": "e5d0bb8871668f20de8f3c94b5ae3f372346bc6e",
"versionType": "git"
},
{
"status": "affected",
"version": "2906f66a5682e5670a5eefe991843689b8d8563f",
"lessThan": "2f75c0faa3361b28e36cc0512b3299e163e25789",
"versionType": "git"
}
],
"programFiles": [
"net/netfilter/ipvs/ip_vs_proto_sctp.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.34"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "2.6.34",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver",
"lessThanOrEqual": "7.1.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"net/netfilter/ipvs/ip_vs_proto_sctp.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-08-15T06:21:01.053",
"references": [
{
"url": "https://git.kernel.org/stable/c/247d055504dcc852e539b9f7f30d19f9741474bf",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/290e9e8389b556efc603522e28bd1543846aa336",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/2f75c0faa3361b28e36cc0512b3299e163e25789",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/9cb5ac594ca76d3a71803b23b74c835b0721e628",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/9f94573ab962a9e81954b755da016fa3cd2f5039",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/a4a2d2e483d79cc2ad3a170674cf159644acf22b",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/d2b8b1557ec07ea1bb5dddbceaf4dfe63d388e27",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/e5d0bb8871668f20de8f3c94b5ae3f372346bc6e",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nipvs: use parsed transport offset in SCTP state lookup\n\nset_sctp_state() reads the SCTP chunk header again in order to drive the\nIPVS SCTP state table. For IPv6 it computes the offset with\nsizeof(struct ipv6hdr), while the surrounding IPVS code uses iph.len from\nip_vs_fill_iph_skb(), where ipv6_find_hdr() has already skipped\nextension headers and found the real transport header.\n\nThis makes the state machine read from the wrong offset for IPv6 SCTP\npackets that carry extension headers. For example, an INIT packet with an\n8-byte destination options header can be scheduled correctly by\nsctp_conn_schedule(), but set_sctp_state() reads the first byte of the\nSCTP verification tag as a DATA chunk type. The connection then moves\nfrom NONE to ESTABLISHED instead of INIT1, gets the longer established\ntimeout, and updates the active/inactive destination counters\nincorrectly. This happens even though the SCTP handshake has not\ncompleted.\n\nUse the parsed transport offset passed down from ip_vs_set_state() for\nthe SCTP chunk-header lookup. For IPv4 and IPv6 packets without\nextension headers this preserves the existing offset."
}
],
"lastModified": "2026-08-17T06:17:59.710",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}