CVE-2026-98130
In the Linux kernel, the following vulnerability has been resolved:
sctp: fix a TOCTOU race in SCTP_CMD_TIMER_START
The SCTP_CMD_TIMER_START handler checks timer_pending() before calling timer_reduce(). The timer can expire and detach between these operations, causing timer_reduce() to rearm the timer without taking the association reference required for the newly armed timer.
The timer callback later unconditionally drops its association reference, which can leave the association reference count unbalanced and result in use-after-free during association teardown.
Use the return value of timer_reduce() to determine whether the timer was actually armed. Take the association reference only when timer_reduce() successfully starts a new timer, closing the race between checking the timer state and rearming it.
Leer descripción completaMostrar menos
This issue was reported by Nico Yip (@_cyeaa_) working with TrendAI Zero Day Initiative.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 8.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.58%
- Percentil entre todas las CVEs puntuadas: 46
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access60 %
Inferido por reglas deterministas a partir del vector CVSS y la CWE. Solo orientativo.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/00b841bac10230c557be6b38efc48508198fe23e
- https://git.kernel.org/stable/c/09e7f9290d63178f56095d5c18fb9f9470153db5
- https://git.kernel.org/stable/c/2188569e7e1b0bc3f3b557dc97ab7a02befc11c8
- https://git.kernel.org/stable/c/3205a20f837f5b1f009427ac3d9f706bf8a6fbec
- https://git.kernel.org/stable/c/3d698d1e6c8bc41e3e1707777a016f1bdd07842d
- https://git.kernel.org/stable/c/755d70ca845fd9b87c7b338ae6ae832b08cd0005
- https://git.kernel.org/stable/c/cbf2df9aac4202f9fb0b361a7fe8c79b29fad92c
- https://git.kernel.org/stable/c/e42ba56281ca3ae2dcb3558bebee9a1c9a4831d9
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-98130",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.1,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.2
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "20a785aa52c82246055a089e55df9dac47d67da1",
"lessThan": "cbf2df9aac4202f9fb0b361a7fe8c79b29fad92c",
"versionType": "git"
},
{
"status": "affected",
"version": "20a785aa52c82246055a089e55df9dac47d67da1",
"lessThan": "3205a20f837f5b1f009427ac3d9f706bf8a6fbec",
"versionType": "git"
},
{
"status": "affected",
"version": "20a785aa52c82246055a089e55df9dac47d67da1",
"lessThan": "755d70ca845fd9b87c7b338ae6ae832b08cd0005",
"versionType": "git"
},
{
"status": "affected",
"version": "20a785aa52c82246055a089e55df9dac47d67da1",
"lessThan": "09e7f9290d63178f56095d5c18fb9f9470153db5",
"versionType": "git"
},
{
"status": "affected",
"version": "20a785aa52c82246055a089e55df9dac47d67da1",
"lessThan": "e42ba56281ca3ae2dcb3558bebee9a1c9a4831d9",
"versionType": "git"
},
{
"status": "affected",
"version": "20a785aa52c82246055a089e55df9dac47d67da1",
"lessThan": "00b841bac10230c557be6b38efc48508198fe23e",
"versionType": "git"
},
{
"status": "affected",
"version": "20a785aa52c82246055a089e55df9dac47d67da1",
"lessThan": "3d698d1e6c8bc41e3e1707777a016f1bdd07842d",
"versionType": "git"
},
{
"status": "affected",
"version": "20a785aa52c82246055a089e55df9dac47d67da1",
"lessThan": "2188569e7e1b0bc3f3b557dc97ab7a02befc11c8",
"versionType": "git"
},
{
"status": "affected",
"version": "9c0a4652f750afe3b4468cbcd9335b244ce2facd",
"versionType": "git"
},
{
"status": "affected",
"version": "70989e501fbce502198d82da88358ce453575a05",
"versionType": "git"
},
{
"status": "affected",
"version": "085bb270b4b1168c93afb37bbafc881207d15443",
"versionType": "git"
},
{
"status": "affected",
"version": "4.19.126",
"lessThan": "4.20",
"versionType": "semver"
},
{
"status": "affected",
"version": "5.4.44",
"lessThan": "5.5",
"versionType": "semver"
},
{
"status": "affected",
"version": "5.6.16",
"lessThan": "5.7",
"versionType": "semver"
}
],
"programFiles": [
"net/sctp/sm_sideeffect.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "5.7"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "5.7",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.271",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.222",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.189",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.158",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.111",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.53",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.7",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"net/sctp/sm_sideeffect.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-25T11:17:44.380",
"references": [
{
"url": "https://git.kernel.org/stable/c/00b841bac10230c557be6b38efc48508198fe23e",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/09e7f9290d63178f56095d5c18fb9f9470153db5",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/2188569e7e1b0bc3f3b557dc97ab7a02befc11c8",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/3205a20f837f5b1f009427ac3d9f706bf8a6fbec",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/3d698d1e6c8bc41e3e1707777a016f1bdd07842d",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/755d70ca845fd9b87c7b338ae6ae832b08cd0005",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/cbf2df9aac4202f9fb0b361a7fe8c79b29fad92c",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/e42ba56281ca3ae2dcb3558bebee9a1c9a4831d9",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Undergoing Analysis",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: fix a TOCTOU race in SCTP_CMD_TIMER_START\n\nThe SCTP_CMD_TIMER_START handler checks timer_pending() before calling\ntimer_reduce(). The timer can expire and detach between these operations,\ncausing timer_reduce() to rearm the timer without taking the association\nreference required for the newly armed timer.\n\nThe timer callback later unconditionally drops its association reference,\nwhich can leave the association reference count unbalanced and result in\nuse-after-free during association teardown.\n\nUse the return value of timer_reduce() to determine whether the timer was\nactually armed. Take the association reference only when timer_reduce()\nsuccessfully starts a new timer, closing the race between checking the\ntimer state and rearming it.\n\nThis issue was reported by Nico Yip (@_cyeaa_) working with TrendAI Zero\nDay Initiative."
}
],
"lastModified": "2026-10-03T11:18:34.857",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}