CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing

Greg Kroah-Hartman <[email protected]>
Newsgroups org.kernel.vger.linux-cve-announce
Message-ID <2026080404-CVE-2026-64564-6762@gregkh>
From: Greg Kroah-Hartman <[email protected]>

Description
===========

In the Linux kernel, the following vulnerability has been resolved:

sctp: don't free the ASCONF's own transport in DEL-IP processing

sctp_process_asconf() caches the transport the ASCONF chunk is processed
against in asconf->transport (== chunk->transport, set once in sctp_rcv()).
For an ASCONF located through its Address Parameter by
__sctp_rcv_asconf_lookup(), that cached transport corresponds to the
Address Parameter, which need not be the packet's source address.

sctp_process_asconf_param() rejects a DEL-IP for the packet source address
(ADDIP D8, SCTP_ERROR_DEL_SRC_IP), but nothing protects asconf->transport.
A single ASCONF can therefore carry, in order:

    [Address Parameter L] [DEL-IP L] [DEL-IP 0.0.0.0]

where L differs from the source. The DEL-IP for L passes the D8 check and
calls sctp_assoc_rm_peer() on the transport that asconf->transport still
points at, freeing it (RCU-deferred). The following wildcard DEL-IP then
reuses the now-dangling asconf->transport in sctp_assoc_set_primary() and
sctp_assoc_del_nonprimary_peers(): set_primary() dereferences the freed
transport (->ipaddr, ->state) and plants the dangling pointer into
asoc->peer.primary_path / active_path, and del_nonprimary_peers(), keeping
only the pointer that is no longer on the list, removes every real
transport, leaving the association with a transport_count of 0 and
primary_path/active_path pointing at freed memory.

Reject a DEL-IP that targets the transport the ASCONF is being processed
against, mirroring the existing source-address guard, so the wildcard
branch can never reuse a freed transport.

The Linux kernel CVE team has assigned CVE-2026-64564 to this issue.


Affected and fixed versions
===========================

	Issue introduced in 2.6.25 with commit 42e30bf3463cd37d73839376662cb79b4d5c416c and fixed in 6.6.148 with commit fedeb4468987bcaff85fe3061de5ae052d414740
	Issue introduced in 2.6.25 with commit 42e30bf3463cd37d73839376662cb79b4d5c416c and fixed in 6.12.101 with commit 74e8f3e7114f0e26d1b2c4c048044db9fcc27603
	Issue introduced in 2.6.25 with commit 42e30bf3463cd37d73839376662cb79b4d5c416c and fixed in 6.18.42 with commit 85aca407c560aba81b5ce9d3d6cf94c74077d19b
	Issue introduced in 2.6.25 with commit 42e30bf3463cd37d73839376662cb79b4d5c416c and fixed in 7.1.6 with commit d136b29bf91dd8e3161281b87de597b7311d9462
	Issue introduced in 2.6.25 with commit 42e30bf3463cd37d73839376662cb79b4d5c416c and fixed in 7.2-rc5 with commit 9b2854f86f0b56e9027d68e7a3fc909d1a9b566f

Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.

Unaffected versions might change over time as fixes are backported to
older supported kernel versions.  The official CVE entry at
	https://cve.org/CVERecord/?id=CVE-2026-64564
will be updated if fixes are backported, please check that for the most
up to date information about this issue.


Affected files
==============

The file(s) affected by this issue are:
	net/sctp/sm_make_chunk.c


Mitigation
==========

The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes.  Individual
changes are never tested alone, but rather are part of a larger kernel
release.  Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all.  If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
	https://git.kernel.org/stable/c/fedeb4468987bcaff85fe3061de5ae052d414740
	https://git.kernel.org/stable/c/74e8f3e7114f0e26d1b2c4c048044db9fcc27603
	https://git.kernel.org/stable/c/85aca407c560aba81b5ce9d3d6cf94c74077d19b
	https://git.kernel.org/stable/c/d136b29bf91dd8e3161281b87de597b7311d9462
	https://git.kernel.org/stable/c/9b2854f86f0b56e9027d68e7a3fc909d1a9b566f
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.