---
cve: "CVE-2026-89478"
severity: "CRITICAL"
cvss: 9.8
epss: "0.5%"
vendor: "Linux"
kev: false
exploited: false
published: "2026-09-11 19:43:34"
tags: [cve, security, critical]
source: tsecurity.de CVE-Dossier
exported: "2026-09-20T15:18:37+02:00"
---

# CVE-2026-89478

> 9.8 CRITICAL

## Beschreibung

In the Linux kernel, the following vulnerability has been resolved:

sctp: drop a chunk if its transport was removed

sctp_rcv() resolves the transport once per packet and leaves it in
chunk->transport. The lookup reference, or the one sctp_add_backlog() takes
if the socket is owned by userspace, keeps it around until the chunk has
been processed.

An authenticated ASCONF DEL-IP can remove it in the meantime.
sctp_assoc_rm_peer() takes the transport out of the association and calls
sctp_transport_free(), which tags it dead and drops the reference the
association held. There is a window on both paths: the packet can sit on
the socket backlog, and on the direct path the lookup completes before
bh_lock_sock().

The DATA chunk in that packet puts the removed transport back into
asoc->peer.last_data_from. Once the packet is done that reference goes
away and the transport is freed by RCU, so the next delayed SACK carries
the pointer into the SACK chunk and sctp_outq_select_transport() reads the
freed transport's state.

Drop the chunk in sctp_inq_push(), next to the existing rcvr->dead check.
Both paths reach it with the association's socket lock held. The peer
retransmits it.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## Patch verfügbar (OSV)

- Kernel ≥ 5.10.270
- Kernel ≥ 5.15.221
- Kernel ≥ 6.1.188
- Kernel ≥ 6.6.157
- Kernel ≥ 6.12.109
- Kernel ≥ 6.18.50
- Kernel ≥ 7.2.4

## Referenzen

- <https://git.kernel.org/stable/c/3fc072e7cb4a0ff251d13cfc2d24f62489cd9386>
- <https://git.kernel.org/stable/c/d7cb5ad832095dc4becfdb2a36007ffd50e49fb0>
- <https://git.kernel.org/stable/c/0422b092a3d43ca462932ff9f747731ca078d1d4>
- <https://git.kernel.org/stable/c/928fd7920ba37cc5637a211b9be979083413a2fa>
- <https://git.kernel.org/stable/c/c6c86a5e62a4fec36692ddd64b9144b660f71f96>
- <https://git.kernel.org/stable/c/1035bdef1efb9b1076d1a57b81e08c637ff08ecc>
- <https://git.kernel.org/stable/c/3537961df2163258bddc230db0e18dc14e925ea6>
- <https://git.kernel.org/stable/c/03a9d10ecf71f54b2af8020935f2033d4a132be5>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-89478) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
