Linux Kernel Vulnerability in SCTP Implementation
CVE-2026-80890

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
4 September 2026

What is CVE-2026-80890?

A vulnerability within the Linux kernel's SCTP implementation allows the acceptance of expired cookies due to inadequate cookie expiration checks when an association is already established. The flawed logic fails to enforce cookie expiration according to RFC 9260 guidelines, permitting improper handling of stale cookies that can potentially restart an association. This vulnerability can lead to significant exposure, allowing replay attacks and unauthorized actions in an SCTP communication environment.

Affected Version(s)

Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2

Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2

Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 817cffdbdbdf50e1f2b016599d1897de3ca54964

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.