TOCTOU Race Condition in Linux Kernel Affecting SCTP Functionality
CVE-2026-98130
Currently unrated
What is CVE-2026-98130?
A race condition exists in the SCTP_CMD_TIMER_START handler of the Linux kernel, where the timer state can change after checking if it is pending, leading to potential use-after-free errors. The vulnerability arises when timer_reduce() is called without ensuring the timer was successfully armed, which can create inconsistencies in the association reference count during teardown. This issue has been addressed in recent kernel updates.
Affected Version(s)
Linux 20a785aa52c82246055a089e55df9dac47d67da1
Linux 20a785aa52c82246055a089e55df9dac47d67da1 < 00b841bac10230c557be6b38efc48508198fe23e
Linux 20a785aa52c82246055a089e55df9dac47d67da1 < 3d698d1e6c8bc41e3e1707777a016f1bdd07842d