Количество 24
Количество 24
GHSA-xw85-w2q2-369x
In the Linux kernel, the following vulnerability has been resolved: sctp: don't free the ASCONF's own transport in DEL-IP processing sctp_process_asconf() caches the transport the ASCONF chunk is processed against in asconf->transport (== chunk->transport, set once in sctp_rcv()). For an ASCONF located through its Address Parameter by __sctp_rcv_asconf_lookup(), that cached transport corresponds to the Address Parameter, which need not be the packet's source address. sctp_process_asconf_param() rejects a DEL-IP for the packet source address (ADDIP D8, SCTP_ERROR_DEL_SRC_IP), but nothing protects asconf->transport. A single ASCONF can therefore carry, in order: [Address Parameter L] [DEL-IP L] [DEL-IP 0.0.0.0] where L differs from the source. The DEL-IP for L passes the D8 check and calls sctp_assoc_rm_peer() on the transport that asconf->transport still points at, freeing it (RCU-deferred). The following wildcard DEL-IP then reuses the now-dangling asconf->transport in sctp...
CVE-2026-64564
In the Linux kernel, the following vulnerability has been resolved: sctp: don't free the ASCONF's own transport in DEL-IP processing sctp_process_asconf() caches the transport the ASCONF chunk is processed against in asconf->transport (== chunk->transport, set once in sctp_rcv()). For an ASCONF located through its Address Parameter by __sctp_rcv_asconf_lookup(), that cached transport corresponds to the Address Parameter, which need not be the packet's source address. sctp_process_asconf_param() rejects a DEL-IP for the packet source address (ADDIP D8, SCTP_ERROR_DEL_SRC_IP), but nothing protects asconf->transport. A single ASCONF can therefore carry, in order: [Address Parameter L] [DEL-IP L] [DEL-IP 0.0.0.0] where L differs from the source. The DEL-IP for L passes the D8 check and calls sctp_assoc_rm_peer() on the transport that asconf->transport still points at, freeing it (RCU-deferred). The following wildcard DEL-IP then reuses the now-dangling asconf->transport in sctp_assoc_se...
CVE-2026-64564
In the Linux kernel, the following vulnerability has been resolved: sctp: don't free the ASCONF's own transport in DEL-IP processing sctp_process_asconf() caches the transport the ASCONF chunk is processed against in asconf->transport (== chunk->transport, set once in sctp_rcv()). For an ASCONF located through its Address Parameter by __sctp_rcv_asconf_lookup(), that cached transport corresponds to the Address Parameter, which need not be the packet's source address. sctp_process_asconf_param() rejects a DEL-IP for the packet source address (ADDIP D8, SCTP_ERROR_DEL_SRC_IP), but nothing protects asconf->transport. A single ASCONF can therefore carry, in order: [Address Parameter L] [DEL-IP L] [DEL-IP 0.0.0.0] where L differs from the source. The DEL-IP for L passes the D8 check and calls sctp_assoc_rm_peer() on the transport that asconf->transport still points at, freeing it (RCU-deferred). The following wildcard DEL-IP then reuses the now-dangling asconf->transport in sctp_assoc_se...
CVE-2026-64564
In the Linux kernel, the following vulnerability has been resolved: sctp: don't free the ASCONF's own transport in DEL-IP processing sctp_process_asconf() caches the transport the ASCONF chunk is processed against in asconf->transport (== chunk->transport, set once in sctp_rcv()). For an ASCONF located through its Address Parameter by __sctp_rcv_asconf_lookup(), that cached transport corresponds to the Address Parameter, which need not be the packet's source address. sctp_process_asconf_param() rejects a DEL-IP for the packet source address (ADDIP D8, SCTP_ERROR_DEL_SRC_IP), but nothing protects asconf->transport. A single ASCONF can therefore carry, in order: [Address Parameter L] [DEL-IP L] [DEL-IP 0.0.0.0] where L differs from the source. The DEL-IP for L passes the D8 check and calls sctp_assoc_rm_peer() on the transport that asconf->transport still points at, freeing it (RCU-deferred). The following wildcard DEL-IP then reuses the now-dangling asconf->transport in sctp_as
CVE-2026-64564
sctp: don't free the ASCONF's own transport in DEL-IP processing
CVE-2026-64564
In the Linux kernel, the following vulnerability has been resolved: s ...
BDU:2026-11391
Уязвимость функции sctp_process_asconf_param() модуля net/sctp/sm_make_chunk.c ядра операционных систем Linux, позволяющая нарушителю повысить свои привилегии до уровня root
SUSE-SU-2026:4259-1
Security update for the Linux Kernel (Live Patch 56 for SUSE Linux Enterprise 15 SP4)
SUSE-SU-2026:4255-1
Security update for the Linux Kernel (Live Patch 57 for SUSE Linux Enterprise 15 SP4)
SUSE-SU-2026:4256-1
Security update for the Linux Kernel (Live Patch 30 for SUSE Linux Enterprise 15 SP5)
SUSE-SU-2026:4244-1
Security update for the Linux Kernel (Live Patch 39 for SUSE Linux Enterprise 15 SP5)
SUSE-SU-2026:4231-1
Security update for the Linux Kernel (Live Patch 16 for SUSE Linux Enterprise 15 SP6)
SUSE-SU-2026:4170-1
Security update for the Linux Kernel RT (Live Patch 17 for SUSE Linux Enterprise 15 SP7)
SUSE-SU-2026:4258-1
Security update for the Linux Kernel (Live Patch 13 for SUSE Linux Enterprise 15 SP7)
SUSE-SU-2026:4172-1
Security update for the Linux Kernel RT (Live Patch 18 for SUSE Linux Enterprise 15 SP7)
SUSE-SU-2026:3809-1
Security update for the Linux Kernel
SUSE-SU-2026:3593-1
Security update for the Linux Kernel
SUSE-SU-2026:3595-1
Security update for the Linux Kernel
SUSE-SU-2026:3602-1
Security update for the Linux Kernel
SUSE-SU-2026:3594-1
Security update for the Linux Kernel
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-xw85-w2q2-369x In the Linux kernel, the following vulnerability has been resolved: sctp: don't free the ASCONF's own transport in DEL-IP processing sctp_process_asconf() caches the transport the ASCONF chunk is processed against in asconf->transport (== chunk->transport, set once in sctp_rcv()). For an ASCONF located through its Address Parameter by __sctp_rcv_asconf_lookup(), that cached transport corresponds to the Address Parameter, which need not be the packet's source address. sctp_process_asconf_param() rejects a DEL-IP for the packet source address (ADDIP D8, SCTP_ERROR_DEL_SRC_IP), but nothing protects asconf->transport. A single ASCONF can therefore carry, in order: [Address Parameter L] [DEL-IP L] [DEL-IP 0.0.0.0] where L differs from the source. The DEL-IP for L passes the D8 check and calls sctp_assoc_rm_peer() on the transport that asconf->transport still points at, freeing it (RCU-deferred). The following wildcard DEL-IP then reuses the now-dangling asconf->transport in sctp... | CVSS3: 9.8 | 1% Низкий | около 2 месяцев назад | |
CVE-2026-64564 In the Linux kernel, the following vulnerability has been resolved: sctp: don't free the ASCONF's own transport in DEL-IP processing sctp_process_asconf() caches the transport the ASCONF chunk is processed against in asconf->transport (== chunk->transport, set once in sctp_rcv()). For an ASCONF located through its Address Parameter by __sctp_rcv_asconf_lookup(), that cached transport corresponds to the Address Parameter, which need not be the packet's source address. sctp_process_asconf_param() rejects a DEL-IP for the packet source address (ADDIP D8, SCTP_ERROR_DEL_SRC_IP), but nothing protects asconf->transport. A single ASCONF can therefore carry, in order: [Address Parameter L] [DEL-IP L] [DEL-IP 0.0.0.0] where L differs from the source. The DEL-IP for L passes the D8 check and calls sctp_assoc_rm_peer() on the transport that asconf->transport still points at, freeing it (RCU-deferred). The following wildcard DEL-IP then reuses the now-dangling asconf->transport in sctp_assoc_se... | CVSS3: 9.8 | 1% Низкий | около 2 месяцев назад | |
CVE-2026-64564 In the Linux kernel, the following vulnerability has been resolved: sctp: don't free the ASCONF's own transport in DEL-IP processing sctp_process_asconf() caches the transport the ASCONF chunk is processed against in asconf->transport (== chunk->transport, set once in sctp_rcv()). For an ASCONF located through its Address Parameter by __sctp_rcv_asconf_lookup(), that cached transport corresponds to the Address Parameter, which need not be the packet's source address. sctp_process_asconf_param() rejects a DEL-IP for the packet source address (ADDIP D8, SCTP_ERROR_DEL_SRC_IP), but nothing protects asconf->transport. A single ASCONF can therefore carry, in order: [Address Parameter L] [DEL-IP L] [DEL-IP 0.0.0.0] where L differs from the source. The DEL-IP for L passes the D8 check and calls sctp_assoc_rm_peer() on the transport that asconf->transport still points at, freeing it (RCU-deferred). The following wildcard DEL-IP then reuses the now-dangling asconf->transport in sctp_assoc_se... | CVSS3: 7.8 | 1% Низкий | около 2 месяцев назад | |
CVE-2026-64564 In the Linux kernel, the following vulnerability has been resolved: sctp: don't free the ASCONF's own transport in DEL-IP processing sctp_process_asconf() caches the transport the ASCONF chunk is processed against in asconf->transport (== chunk->transport, set once in sctp_rcv()). For an ASCONF located through its Address Parameter by __sctp_rcv_asconf_lookup(), that cached transport corresponds to the Address Parameter, which need not be the packet's source address. sctp_process_asconf_param() rejects a DEL-IP for the packet source address (ADDIP D8, SCTP_ERROR_DEL_SRC_IP), but nothing protects asconf->transport. A single ASCONF can therefore carry, in order: [Address Parameter L] [DEL-IP L] [DEL-IP 0.0.0.0] where L differs from the source. The DEL-IP for L passes the D8 check and calls sctp_assoc_rm_peer() on the transport that asconf->transport still points at, freeing it (RCU-deferred). The following wildcard DEL-IP then reuses the now-dangling asconf->transport in sctp_as | CVSS3: 9.8 | 1% Низкий | около 2 месяцев назад | |
CVE-2026-64564 sctp: don't free the ASCONF's own transport in DEL-IP processing | CVSS3: 9.8 | 1% Низкий | около 2 месяцев назад | |
CVE-2026-64564 In the Linux kernel, the following vulnerability has been resolved: s ... | CVSS3: 9.8 | 1% Низкий | около 2 месяцев назад | |
BDU:2026-11391 Уязвимость функции sctp_process_asconf_param() модуля net/sctp/sm_make_chunk.c ядра операционных систем Linux, позволяющая нарушителю повысить свои привилегии до уровня root | CVSS3: 9.8 | 1% Низкий | 2 месяца назад | |
SUSE-SU-2026:4259-1 Security update for the Linux Kernel (Live Patch 56 for SUSE Linux Enterprise 15 SP4) | 6 дней назад | |||
SUSE-SU-2026:4255-1 Security update for the Linux Kernel (Live Patch 57 for SUSE Linux Enterprise 15 SP4) | 6 дней назад | |||
SUSE-SU-2026:4256-1 Security update for the Linux Kernel (Live Patch 30 for SUSE Linux Enterprise 15 SP5) | 6 дней назад | |||
SUSE-SU-2026:4244-1 Security update for the Linux Kernel (Live Patch 39 for SUSE Linux Enterprise 15 SP5) | 6 дней назад | |||
SUSE-SU-2026:4231-1 Security update for the Linux Kernel (Live Patch 16 for SUSE Linux Enterprise 15 SP6) | 7 дней назад | |||
SUSE-SU-2026:4170-1 Security update for the Linux Kernel RT (Live Patch 17 for SUSE Linux Enterprise 15 SP7) | 10 дней назад | |||
SUSE-SU-2026:4258-1 Security update for the Linux Kernel (Live Patch 13 for SUSE Linux Enterprise 15 SP7) | 6 дней назад | |||
SUSE-SU-2026:4172-1 Security update for the Linux Kernel RT (Live Patch 18 for SUSE Linux Enterprise 15 SP7) | 10 дней назад | |||
SUSE-SU-2026:3809-1 Security update for the Linux Kernel | 29 дней назад | |||
SUSE-SU-2026:3593-1 Security update for the Linux Kernel | около 1 месяца назад | |||
SUSE-SU-2026:3595-1 Security update for the Linux Kernel | около 1 месяца назад | |||
SUSE-SU-2026:3602-1 Security update for the Linux Kernel | около 1 месяца назад | |||
SUSE-SU-2026:3594-1 Security update for the Linux Kernel | около 1 месяца назад |
Уязвимостей на страницу