Bug 2510890 (CVE-2026-64564) - CVE-2026-64564 kernel: sctp: don't free the ASCONF's own transport in DEL-IP processing
Summary: CVE-2026-64564 kernel: sctp: don't free the ASCONF's own transport in DEL-IP ...
Keywords:
Status: NEW
Alias: CVE-2026-64564
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-08-04 07:02 UTC by OSIDB Bzimport
Modified: 2026-09-24 05:52 UTC (History)
18 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2026:69089 0 None None None 2026-09-21 00:56:41 UTC
Red Hat Product Errata RHSA-2026:69837 0 None None None 2026-09-22 03:33:47 UTC
Red Hat Product Errata RHSA-2026:69874 0 None None None 2026-09-22 07:16:37 UTC
Red Hat Product Errata RHSA-2026:69906 0 None None None 2026-09-22 08:28:22 UTC
Red Hat Product Errata RHSA-2026:69908 0 None None None 2026-09-22 10:45:01 UTC
Red Hat Product Errata RHSA-2026:70290 0 None None None 2026-09-22 16:05:06 UTC
Red Hat Product Errata RHSA-2026:70308 0 None None None 2026-09-22 16:05:37 UTC
Red Hat Product Errata RHSA-2026:70482 0 None None None 2026-09-23 01:39:23 UTC
Red Hat Product Errata RHSA-2026:70483 0 None None None 2026-09-23 00:25:01 UTC
Red Hat Product Errata RHSA-2026:70484 0 None None None 2026-09-23 02:24:19 UTC
Red Hat Product Errata RHSA-2026:71016 0 None None None 2026-09-23 18:08:45 UTC
Red Hat Product Errata RHSA-2026:71213 0 None None None 2026-09-24 01:02:42 UTC
Red Hat Product Errata RHSA-2026:71232 0 None None None 2026-09-24 05:52:45 UTC
Red Hat Product Errata RHSA-2026:71233 0 None None None 2026-09-24 03:01:06 UTC

Description OSIDB Bzimport 2026-08-04 07:02:12 UTC
In the Linux kernel, the following vulnerability has been resolved:

sctp: don't free the ASCONF's own transport in DEL-IP processing

sctp_process_asconf() caches the transport the ASCONF chunk is processed
against in asconf->transport (== chunk->transport, set once in sctp_rcv()).
For an ASCONF located through its Address Parameter by
__sctp_rcv_asconf_lookup(), that cached transport corresponds to the
Address Parameter, which need not be the packet's source address.

sctp_process_asconf_param() rejects a DEL-IP for the packet source address
(ADDIP D8, SCTP_ERROR_DEL_SRC_IP), but nothing protects asconf->transport.
A single ASCONF can therefore carry, in order:

    [Address Parameter L] [DEL-IP L] [DEL-IP 0.0.0.0]

where L differs from the source. The DEL-IP for L passes the D8 check and
calls sctp_assoc_rm_peer() on the transport that asconf->transport still
points at, freeing it (RCU-deferred). The following wildcard DEL-IP then
reuses the now-dangling asconf->transport in sctp_assoc_set_primary() and
sctp_assoc_del_nonprimary_peers(): set_primary() dereferences the freed
transport (->ipaddr, ->state) and plants the dangling pointer into
asoc->peer.primary_path / active_path, and del_nonprimary_peers(), keeping
only the pointer that is no longer on the list, removes every real
transport, leaving the association with a transport_count of 0 and
primary_path/active_path pointing at freed memory.

Reject a DEL-IP that targets the transport the ASCONF is being processed
against, mirroring the existing source-address guard, so the wildcard
branch can never reuse a freed transport.

Comment 1 Mauro Matteo Cascella 2026-08-04 08:59:08 UTC
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2026080404-CVE-2026-64564-6762@gregkh/T

Comment 4 Jon Orris 2026-09-21 00:56:39 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:69089 https://access.redhat.com/errata/RHSA-2026:69089

Comment 6 Jon Orris 2026-09-22 03:33:46 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service

Via RHSA-2026:69837 https://access.redhat.com/errata/RHSA-2026:69837

Comment 7 Jon Orris 2026-09-22 07:16:35 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On

Via RHSA-2026:69874 https://access.redhat.com/errata/RHSA-2026:69874

Comment 8 Jon Orris 2026-09-22 08:28:20 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On

Via RHSA-2026:69906 https://access.redhat.com/errata/RHSA-2026:69906

Comment 9 Jon Orris 2026-09-22 10:44:59 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions

Via RHSA-2026:69908 https://access.redhat.com/errata/RHSA-2026:69908

Comment 10 Jon Orris 2026-09-22 16:05:05 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7 Extended Lifecycle Support

Via RHSA-2026:70290 https://access.redhat.com/errata/RHSA-2026:70290

Comment 11 Jon Orris 2026-09-22 16:05:36 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7 Extended Lifecycle Support

Via RHSA-2026:70308 https://access.redhat.com/errata/RHSA-2026:70308

Comment 12 Jon Orris 2026-09-23 00:24:59 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2026:70483 https://access.redhat.com/errata/RHSA-2026:70483

Comment 13 Jon Orris 2026-09-23 01:39:21 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2026:70482 https://access.redhat.com/errata/RHSA-2026:70482

Comment 14 Jon Orris 2026-09-23 02:24:17 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:70484 https://access.redhat.com/errata/RHSA-2026:70484

Comment 15 Jon Orris 2026-09-23 18:08:43 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:71016 https://access.redhat.com/errata/RHSA-2026:71016

Comment 16 Jon Orris 2026-09-24 01:02:40 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:71213 https://access.redhat.com/errata/RHSA-2026:71213

Comment 17 Jon Orris 2026-09-24 03:01:04 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:71233 https://access.redhat.com/errata/RHSA-2026:71233

Comment 18 Jon Orris 2026-09-24 05:52:43 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:71232 https://access.redhat.com/errata/RHSA-2026:71232


Note You need to log in before you can comment on or make changes to this bug.