Denial of Service Vulnerability in Linux Kernel's SCTP Module
CVE-2026-98123

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
25 September 2026

What is CVE-2026-98123?

The Linux kernel's SCTP module contains a vulnerability that can be exploited to achieve a remote denial of service. An attacker can send a specially crafted ASCONF-ACK message that leads to a desynchronization in the way SCTP parameters are processed. This desynchronization can result in a soft lockup where the consumer spins in an infinite loop without making progress, effectively causing the system to hang. Additionally, a flaw allows the processing of SCTP_PARAM_ERR_CAUSE parameters without adequate length checks, potentially leading to out-of-bounds reads. It is crucial to ensure proper padding and verification in order to maintain system integrity and prevent exploitation.

Affected Version(s)

Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2

Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 3be02999ab9131a4b96eb1eda4ca48b1cea80f03

Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 7ba84e2971d208a2d6413a334ec28a8a32cdce0f

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.