From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 09AD2582B97 for ; Fri, 11 Sep 2026 19:53:26 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156415; cv=none; b=MsaCNMPf5gGA3GpNwPDe0KhLcZ2jR19QA+yND/FNHUerjC9hIgTAApBL7GApMFWjFwLFqfheMSOAqsYQPBFlwKS81HHN4QM8Gn6noTkY+1mY86ozVKJKudrsvm1zC7HpHZVFAAKihH7q6CeS4Ku1BS5vdpIGnJ1RxEyjDiCX0lc= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156415; c=relaxed/simple; bh=tNXsqMMapOxZW7QPPYSg2JFCAZ8ws+UCuWlTqDQD5Ik=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=YNl9kDpyFuPyrqHH/YnYfuw3fxbdU6o1Rgbs+h0JBjgiEj6Q/cujrooQygoC9Pb67GV269y1hZYDBb67iNvMoyNsGxoDbv6bYsfSKu+e9Zt86inHvnNlWU+EvxBwHKtjz061v3Hfi4nSPSP8vlurZ23/N0V8s66imsRQT08GVC4= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=eG0aezEk; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="eG0aezEk" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 7A7DD1F0089A; Fri, 11 Sep 2026 19:53:24 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1789156405; bh=efCFfWJ/jwy0Imso0RBlU/zUfDVu397Bq53K/w/R/r8=; h=From:To:Cc:Subject:Date:Reply-To; b=eG0aezEk/mABqHoib4QjCZdwHrBTFZo6uKqryotV2eWBo/4rGeeLxQEfOkq4r8ciF XYiY4WE/trddPchZ9lXBC/xslYckocL9OukqoN8fu4bC6Rll6mvLTlTRtZ8lHk0W6K D0Z6+w8U1LGFR+4D727ktgLC/3LkfCiuW+4oz4mI= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-89479: sctp: stop processing a packet once its association is deleted Date: Fri, 11 Sep 2026 21:42:48 +0200 Message-ID: <2026091105-CVE-2026-89479-caef@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=3696; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=ef2YGNdOYC1lVw9VZe13Lak9nz1mM9/zNEHRssWM65A=; b=owGbwMvMwCRo6H6F97bub03G02pJDFlLIgMbHj461a9m1fu8i1N516U1UafeN8maqr2+Jf/c2 2/19k67jlgWBkEmBlkxRZYv23iO7q84pOhlaHsaZg4rE8gQBi5OAZjIvWkMc8VTJ0SJ/Djb8efJ tbLgrNlHGffO4GRYcNHry9pbPwsWdD2bUiqR5FzlseyFEwA= X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: sctp: stop processing a packet once its association is deleted sctp_endpoint_bh_rcv() looks the association up only when chunk->asoc is NULL, and caches the result in chunk->asoc and chunk->transport without taking a reference. A packet that matches no association is handed to the endpoint, so a peer can bundle COOKIE ECHO, SHUTDOWN and SHUTDOWN ACK in one packet. The COOKIE ECHO creates the association, the SHUTDOWN chunk caches it, and with the outqueue empty the SHUTDOWN ACK reaches sctp_sf_do_9_2_final(), so the association and its transports are freed. The endpoint loop has no counterpart to the asoc->base.dead check in sctp_assoc_bh_rcv(). The next chunk writes to last_time_heard in the freed transport and is then passed to sctp_do_sm() with the freed association. The transport is freed through RCU, so this needs the packet to come off the socket backlog, where the loop runs in task context. The endpoint loop cannot do the same check: it holds no reference on the association, so reading asoc->base.dead would itself be a use-after-free. Mark the packet for discard in the command interpreter, just before it deletes the association. That is also before sctp_inq_free() releases the chunk on the association receive path. sctp_sf_do_5_2_4_dupcook() issues SCTP_CMD_DELETE_TCB for the temporary association, while the one the packet belongs to stays alive. A restarting peer can bundle DATA behind its COOKIE ECHO, so compare against chunk->asoc and leave that case alone. The Linux kernel CVE team has assigned CVE-2026-89479 to this issue. Affected and fixed versions =========================== Issue introduced in 2.6.12 with commit 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and fixed in 6.12.109 with commit ee3f04cf566f6041aa9a0360494fd8db5ade383a Issue introduced in 2.6.12 with commit 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and fixed in 6.18.50 with commit fa306a40e716c5abcd967475459ce1ebd56e5115 Issue introduced in 2.6.12 with commit 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and fixed in 7.2.4 with commit a713e1b3a265f180ad25a08e17be15d67a2f7149 Issue introduced in 2.6.12 with commit 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and fixed in 7.3-rc1 with commit 47e15a8d12e366d0d261bcbc394394f44418938d Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-89479 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: net/sctp/sm_sideeffect.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/ee3f04cf566f6041aa9a0360494fd8db5ade383a https://git.kernel.org/stable/c/fa306a40e716c5abcd967475459ce1ebd56e5115 https://git.kernel.org/stable/c/a713e1b3a265f180ad25a08e17be15d67a2f7149 https://git.kernel.org/stable/c/47e15a8d12e366d0d261bcbc394394f44418938d