PT-2026-51722 · Linux+2 · Linux Kernel+2
CVE-2026-52929
·
Published
2026-06-09
·
Updated
2026-09-12
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the SCTP implementation where the system fails to fully roll back the state when an
ADD OUT STREAMS request is denied. In such cases, the system only shrinks queued chunks and lowers the outcnt variable, leaving behind removed stream metadata. This allows a subsequent re-addition attempt to reuse a stale extension, leading to a null-pointer dereference within the scheduler get path. A null-pointer dereference occurs when the software attempts to read from a memory address that is null, typically resulting in a system crash.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linuxmint
Linux Kernel
Ubuntu