PT-2026-51717 · Linux+3 · Linux Kernel+3

·

CVE-2026-52924

·

Published

2026-06-04

·

Updated

2026-09-12

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to June 2026
Description A use-after-free flaw exists in the Linux kernel's Stream Control Transmission Protocol (SCTP) implementation. The issue occurs within the sctp sf do 5 2 6 stale() function when the system processes a Stale Cookie ERROR during the setup or reconfiguration of an SCTP association. In this scenario, the association is rolled back from COOKIE ECHOED to COOKIE WAIT, and while sctp stream update() replaces the stream table, it fails to invalidate the stream->out curr variable. Consequently, out curr may point to a freed sctp stream out entry. Subsequent SCTP scheduler dequeue paths that rely on stream->out curr->ext can trigger a use-after-free condition after the old stream state is released via sctp stream free(). A remote attacker could exploit this by sending specially crafted SCTP packets, potentially leading to a system crash, Denial of Service (DoS), or local root privilege escalation.
Recommendations Update the Linux kernel to a version released after June 2026 to ensure the association outqueue is fully purged during Stale Cookie handling. As a temporary mitigation, restrict the use of the SCTP module to minimize the risk of exploitation.

Exploit

Fix

DoS

LPE

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:59723
ALSA-2026:59737
ALSA-2026:59821
AZL-90609
BDU:2026-13901
CVE-2026-52924
ECHO-A021-65A7-CBE1
OPENSUSE-SU-2026:21388-1
RHSA-2026:59737
RHSA-2026:59821
SUSE-SU-2026:22742-1
SUSE-SU-2026:22769-1
SUSE-SU-2026:22809-1
SUSE-SU-2026:22810-1
SUSE-SU-2026:22812-1
SUSE-SU-2026:22835-1
SUSE-SU-2026:22903-1
SUSE-SU-2026:22904-1
SUSE-SU-2026:2840-1
SUSE-SU-2026:2841-1
SUSE-SU-2026:3044-1
SUSE-SU-2026:3089-1
SUSE-SU-2026:3130-1
SUSE-SU-2026:3156-1
SUSE-SU-2026:3166-1
USN-8629-1
USN-8629-2
USN-8629-3
USN-8630-1
USN-8630-2
USN-8630-3
USN-8630-4
USN-8630-5
USN-8631-1
USN-8631-2
USN-8631-3
USN-8631-4
USN-8633-1
USN-8633-2
USN-8635-1
USN-8636-1
USN-8636-2
USN-8637-1
USN-8645-1
USN-8656-1
USN-8660-1
USN-8661-1
USN-8661-2
USN-8661-3
USN-8661-4
USN-8663-1
USN-8664-1
USN-8666-1
USN-8666-2
USN-8666-3
USN-8667-1
USN-8669-1
USN-8715-1
USN-8728-1

Affected Products

Linuxmint
Linux Kernel
Rocky Linux
Ubuntu