Linux Kernel Vulnerability in SCTP Heartbeat Acknowledgment Process
CVE-2026-74688

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
22 August 2026

What is CVE-2026-74688?

A vulnerability exists in the Linux kernel's Stream Control Transmission Protocol (SCTP) due to improper handling of control chunks during the heartbeat acknowledgment process. This issue arises when a transport is removed while a control chunk retains a dangling pointer to the transport. The failure to clear this pointer can lead to a use-after-free situation when the queued control chunk is eventually transmitted, potentially allowing an attacker to exploit this condition to execute arbitrary code or crash the system. The vulnerability highlights the importance of proper reference management in the kernel to maintain system stability and security.

Affected Version(s)

Linux 8a07eb0a50aebc8c95478d49c28c7f8419a26cef

Linux 8a07eb0a50aebc8c95478d49c28c7f8419a26cef

Linux 8a07eb0a50aebc8c95478d49c28c7f8419a26cef < 936658ec41c28c397ef390140e02d4c91ade92f0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.