User After Free Vulnerability in Linux Kernel SCTP Control Socket
CVE-2026-68162

7.8HIGH

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
10 August 2026

Badges

πŸ”₯ Trending nowπŸ“ˆ TrendedπŸ“ˆ Score: 1,540

What is CVE-2026-68162?

CVE-2026-68162 refers to a user-after-free vulnerability in the Linux kernel's SCTP (Stream Control Transmission Protocol) control socket. SCTP is a transport layer protocol that provides reliable, message-oriented communication, commonly used in telecommunication systems and other scenarios requiring high reliability. This particular vulnerability arises during the teardown of network namespaces when sysctl parameters related to SCTP authentication are being manipulated, potentially leading to a scenario where a previously freed control socket remains accessible. This flaw can be exploited by an attacker, compromising the integrity and availability of the system, thereby posing a significant risk to organizations that rely on the Linux kernel for critical operations.

Potential impact of CVE-2026-68162

  1. Remote Code Execution: The vulnerability could allow an attacker to execute arbitrary code within the context of the affected system, leading to unauthorized control and potential data breaches.

  2. Denial of Service: Exploitation of this flaw could cause the SCTP control socket to become unstable or crash, resulting in a denial of service for applications relying on the SCTP protocol, thereby impacting service availability.

  3. Data Integrity Compromise: By manipulating the SCTP state through the vulnerable sysctl parameters, attackers may alter or disrupt data transmission processes, leading to integrity violations that compromise the reliability of communications handled by the affected systems.

Affected Version(s)

Linux 10c869a52f266e40f548cc3c565d14930a5edafc < 19573dcddb8819fd68d6cd1f916c1c99c3fa4ff4

Linux dc583e7e5f8515ca489c0df28e4362a70eade382

Linux bd2a2939423566c654545fa3e96a656662a0af9e

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • πŸ“ˆ

    Vulnerability started trending

  • Vulnerability published

  • Vulnerability Reserved

.