Vulnerability in Linux Kernel's SCTP Handling Can Lead to Memory Issues
CVE-2026-64564
What is CVE-2026-64564?
A vulnerability in the Linux kernel's SCTP (Stream Control Transmission Protocol) handling arises when processing Address Configuration (ASCONF) chunks. Specifically, the system allows for a potential memory corruption scenario by failing to protect the transport cached in the ASCONF structure. An improper DELETE-IP request can exploit this weakness, leading to dereferencing freed memory, creating instability in network connections. This issue is critical to address as it can compromise system reliability and pose security risks.
Affected Version(s)
Linux 42e30bf3463cd37d73839376662cb79b4d5c416c
Linux 42e30bf3463cd37d73839376662cb79b4d5c416c < 74e8f3e7114f0e26d1b2c4c048044db9fcc27603
Linux 42e30bf3463cd37d73839376662cb79b4d5c416c < 85aca407c560aba81b5ce9d3d6cf94c74077d19b